AML/CTF Support
Before anything else, your business must be enrolled with AUSTRAC as a reporting entity. From there, an effective AML/CTF Program rests on a clearly articulated risk appetite, a documented methodology, and an enterprise-wide risk assessment that genuinely reflects the business. Controls must be tested and demonstrably operating as designed. Policies translate identified risks into procedures and controls. Appointing an AMLCO and Senior Manager with clear accountability is a legal requirement - and a governance foundation. An obligations register records what must be done, by whom, and when. Deep dives focus attention on areas of heightened risk. Compliance checks and Program reviews test whether the Program is operating as expected. Training equips staff to recognise and report suspicious activity. Transaction monitoring identifies activity warranting further scrutiny. Board and senior management reporting keeps those responsible for oversight informed and accountable. Independent evaluations provide an objective external view of whether the Program is fit for purpose. And underpinning all of this is resourcing - the people, technology, and operating model that give the Program the capacity to function effectively.
The sections below step through the key elements of an AML/CTF Program. This material is general in nature, is not exhaustive, is not legal advice, and is not a substitute for professional legal, risk or compliance advice tailored to your circumstances.
Key components of an effective AML/CTF Program
Need support building or reviewing your AML/CTF Program or any of the key components we outline above?
Get in touchBefore you can build and operate an AML/CTF Program, you must first be enrolled with AUSTRAC as a reporting entity. Enrolment is the mechanism by which AUSTRAC identifies the businesses that are subject to the AML/CTF Act and Rules, and it is a legal obligation - not an optional step.
Australia's AML/CTF framework applies to businesses that provide one or more "designated services" as defined in the AML/CTF Act. If your business provides a designated service, you are a reporting entity and you must enrol with AUSTRAC. Operating as a reporting entity without being enrolled is a breach of the Act.
Tranche 1 and Tranche 2 - what is the difference?
Australia's AML/CTF framework has been extended in two tranches. Understanding which tranche applies to your business determines when your obligations commenced and what is required of you.
Tranche 1:
Tranche 1 covers the sectors that have been subject to Australia's AML/CTF framework since it was first introduced - broadly, financial services, gambling, bullion dealing, and certain remittance and digital currency exchange services. If your business falls within Tranche 1, your AML/CTF obligations have been in place for some time and full compliance is expected now.
Tranche 1 entities should also note that the reforms to the AML/CTF Act and Rules apply to them, and existing Programs will need to be reviewed against the new framework.
Tranche 2:
Tranche 2 extends the AML/CTF framework to a broader range of professional service providers - sectors that have historically been outside the regime but that are recognised internationally as presenting significant ML/TF/PF risk. The Tranche 2 reforms were enacted through the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 and the associated AML/CTF Rules 2025.
Tranche 2 entities include lawyers, accountants, real estate agents, trust and company service providers, and dealers in precious metals and stones. From 1 July 2026, these businesses are required to enrol with AUSTRAC, adopt an AML/CTF Program, conduct customer due diligence, and meet ongoing reporting and record-keeping obligations. A transitional period applies for some obligations - but enrolment and Program adoption are required from commencement on 1 July 2026.
The designated services that capture lawyers, accountants and other Tranche 2 entities are specific and technical. If your business is in any of the Tranche 2 sectors, you should obtain advice on whether the specific services you provide are captured - the categories above are indicative only.
Consider the following actions (as they might apply to your operations):
Australia's AML/CTF framework is built on a risk-based approach. As AUSTRAC describes it, a risk-based approach means that the resources, effort, and scrutiny you apply are proportionate to the level of ML/TF/PF risk you face. Higher-risk customers, products, channels, and jurisdictions attract more rigorous controls and oversight; lower-risk areas can be managed with lighter-touch measures. This principle runs through every element of your Program - from how you assess risk, to how you design controls, to how you test them.
Your risk appetite is the foundation of your AML/CTF Program. It defines the level and type of money laundering, terrorism financing, and proliferation financing risk your organisation is willing to accept in pursuit of its objectives - and the level it is not.
A well-articulated risk appetite does more than satisfy a regulatory requirement. It drives every downstream decision in your Program: which customers you take on, which products you offer, which channels you operate through, and which jurisdictions you engage with. Without it, your risk assessments lack an anchor, your controls lack a rationale, and your board lacks a framework for oversight.
Risk appetite must be set at the board or governing body level. It should be documented, approved, and reviewed regularly - and it must be genuinely reflected in how your business operates. A risk appetite statement that is not embedded in decision-making is not a risk appetite.
Key elements of an effective risk appetite statement:
If your risk appetite has not been formally set, or has not been reviewed since your last risk assessment, that is a gap that needs to be addressed before the rest of your Program can be properly calibrated.
Consider the following actions (as they might apply to your operations):
Developing a formal Risk Appetite Statement for ML/TF/PF and/or update your broader business Risk Appetite Statement to address ML/TF/PF risks and your AML/CTF compliance risks.
A risk assessment methodology (RAM) is the structured approach your organisation uses to identify, analyse, and evaluate ML/TF/PF risks. It determines how you measure risk, how you weight different risk factors, and how you arrive at an overall risk rating for your business.
There is no single prescribed methodology for an EWRA. What stakeholders - including your board, auditors, and regulators - will look for is an approach that is fit for purpose, documented, and defensible. In practice, methodology choices sit on two axes.
The first is how risk is rated:
The second is how risk is analysed and evidenced:
Most credible EWRAs combine elements from both axes. The choice of rating approach is less important than ensuring the methodology is applied consistently, the inputs are sourced, and the reasoning from input to rating is transparent.
Whichever methodology you adopt, it must address the four key risk categories required under the AML/CTF framework (AUSTRAC refers to these as 'factors'): customer risk, designated services risk, channel risk, and jurisdictional risk. Each category should be assessed individually and then brought together - consistently with your RAM - into an enterprise-wide view. For certain businesses that rely upon ACIP exemptions under Australia's AML laws, this may also involve a more detailed methodology on individual customer types.
For organisations that operate across multiple venues, branches, or outposts, your methodology should contemplate how risk is assessed at each location and how those assessments roll up into the enterprise-wide picture. A 'parent' risk assessment captures the overall risk profile of the organisation, while 'child' assessments address the specific risk profile of each venue or branch - reflecting differences in customer base, product mix, geographic location, and local operating environment. Where venues differ materially in their risk exposure, those differences must be reflected in the assessment rather than averaged away. A single enterprise-wide assessment that does not account for venue-level variation will not accurately represent the organisation's true risk profile.
Where your organisation applies weighting or averaging in your assessment, you may find that you need to make informed assumptions or compromises. This could elevate the possibility that higher risk issues are missed - make sure you address that risk by ensuring the appropriate elevation and actioning of issues in these scenarios.
Your methodology should also account for the inherent risk your business faces before controls are applied, and the residual risk that remains after controls are in place. This distinction is critical - it is what allows you to assess whether your controls are adequate, and where gaps exist.
Selecting the right methodology:
The right methodology for your organisation depends on its size, complexity, and the nature of its ML/TF/PF risk exposure. A small, low-complexity business may be well-served by a straightforward qualitative approach. A large, multi-product, multi-jurisdiction business will likely require a more sophisticated framework.
What matters most is that your methodology is applied consistently, documented clearly, and produces a risk assessment that your board and senior management can stand behind.
Consider the following actions (as they might apply to your operations):
Developing a detailed Risk Assessment Methodology that sets out how you identify, assess, rate, weight and treat ML/TF/PF risks presented by your customers, designated services, channels and jurisdictions. You might also consider including in your methodology how you look at other relevant risks related to your employees, your location, third parties in your ecosystem and the threat environment.
Your enterprise-wide risk assessment (EWRA) is the central document of your AML/CTF Program. It brings together your assessment of customer, designated service, channel, and jurisdictional risk (as well as the other risks you have identified in your methodology relevant to your business) into a single, coherent view of your organisation's overall ML/TF/PF risk exposure.
The EWRA should follow your chosen methodology. That means the risk ratings, weightings, and conclusions in your assessment should flow logically from the methodology you have documented and adopted.
What a well-documented EWRA should include:
The EWRA is not a static document. It must be reviewed and updated whenever there is a material change to your business - new designated services, new customer segments, new channels, new jurisdictions, or changes in the regulatory or threat environment. It should be reviewed regularly, informed by your context (the nature of your business, its size and complexity).
Critically, the EWRA must be owned. Someone in your organisation - typically the AML/CTF Compliance Officer (AMLCO) - must be accountable for keeping it current, ensuring it reflects the business as it actually operates, and escalating material changes to the board.
Consider the following actions (as they might apply to your operations):
Compiling your EWRA in a workbook, with separate tabs for each key risk factor area that you assess. Make sure you have a tab that summarises the overarching inherent and residual ML/TF/PF risks. Think of it like your assessor is "following the bouncing ball" as set out in your RAM. Ensure that you clearly link the inherent risks to the controls you have in place to mitigate/manage those risks and document how you have assured yourself that the controls are operating to mitigate the risk. Collate your controls together in a readily accessible library and make sure you have links to each control you have identified for quick access and independent evaluation purposes.
What we expect you will find is that for some organisations, this is a hefty workbook. Technology can be your friend in capturing your assessment - explore your options!
Further reading: Gaming - Customer Risk Assessments · Gaming - Product Risk Assessments · Gaming - Channel Risk Assessments · The Risk Assessment Process - A Diagram
Your AML/CTF Program must include AML/CTF policies - the documented rules, procedures, and standards that govern how your organisation identifies, manages, and mitigates its ML/TF/PF risks. Policies are a significant part of the operational expression of your Program: they translate your risk assessment and risk appetite into day-to-day practice.
Under the AML/CTF Act and Rules, your policies must be appropriate to the nature, size, and complexity of your business and the ML/TF/PF risks you face. They must be kept up to date, and staff must be trained on them.
What your AML/CTF policies should cover:
Consider the following actions (as they might apply to your operations):
The AML/CTF Act and Rules require reporting entities to designate two key roles: an AML/CTF Compliance Officer (AMLCO) and a Senior Manager with responsibility for AML/CTF compliance. These are distinct roles with different functions, and both are required.
The AMLCO:
The AMLCO is responsible for the day-to-day management of the AML/CTF Program. The AMLCO is the person who owns the Program operationally - ensuring it is kept current, that controls are operating as designed, that staff are trained, that suspicious matters are identified and reported, and that the board and senior management are kept informed. In smaller organisations, the AMLCO may perform many of these functions directly. In larger organisations, the AMLCO may oversee a team. Either way, the operational accountability sits with the AMLCO.
The Senior Manager:
The Senior Manager is a member of senior management who is accountable for AML/CTF compliance at the governance level. Where the AMLCO is responsible for how the Program operates day-to-day, the Senior Manager is responsible for ensuring that the Program has the organisational support, resources, and authority it needs to function effectively - and for escalating material AML/CTF issues to the board.
The Senior Manager does not manage the Program operationally - that is the AMLCO's role. The Senior Manager provides the governance layer above the AMLCO: championing the Program at the executive level, ensuring it receives adequate resourcing, and holding the organisation accountable for addressing identified deficiencies. In practice, the Senior Manager is often a Chief Risk Officer, Chief Compliance Officer, Chief Executive Officer, or equivalent - someone with sufficient seniority and authority to drive action across the business.
How the two roles interact:
The AMLCO and Senior Manager are complementary. The AMLCO runs the Program; the Senior Manager ensures the Program has what it needs to run effectively and that the board is appropriately engaged. The AMLCO typically reports to or through the Senior Manager on AML/CTF matters, and the Senior Manager is the conduit between the compliance and risk function and the board. Where the AMLCO identifies a material issue that requires board attention or additional resources, it is the Senior Manager's role to ensure that escalation happens and that it is acted upon.
Who can hold these roles:
The AML/CTF Rules do not prescribe specific qualifications for either role, but both must have sufficient authority, seniority, and competence to perform their respective functions effectively. The AMLCO must have a genuine understanding of the business and its ML/TF/PF risks and the ability to escalate issues and drive remediation. The Senior Manager must have sufficient seniority to hold the organisation accountable and sufficient access to the board to discharge their governance responsibilities. In some smaller organisations, the same person may hold both roles - but care should be taken to ensure that the governance and operational functions are still being performed distinctly.
Consider the following actions (as they might apply to your operations):
Further reading: Stepping Into the AMLCO Role
Controls monitoring and testing are distinct but complementary activities. Monitoring is the ongoing, day-to-day oversight of whether controls are operating as intended. Testing is the periodic, structured assessment of whether controls are designed appropriately and are effective in practice. Both are essential to a well-functioning AML/CTF Program.
Before you can monitor or test a control, it needs to be properly documented. A well-documented control has six key attributes.
Who monitors controls - and how:
Controls Testing:
What controls testing can involve:
Controls testing should be risk-based - meaning the frequency and rigour of testing is proportionate to the level of risk the control is designed to address. Higher-risk areas of your Program warrant more frequent and more rigorous testing. The results of testing must be documented, and any failures or gaps must be escalated and remediated.
Independent vs internal testing:
Controls testing can be conducted internally - by your compliance and risk function or internal audit - or independently, by an external party. Both have a role. Internal testing provides ongoing assurance and allows issues to be identified and addressed quickly. Independent testing provides an objective assessment that is not subject to the same conflicts of interest as internal review.
In some cases, independent testing is not optional. Regulators may require it as part of a remediation program, or as a condition of a licence. Even where it is not required, periodic independent testing is good practice - and demonstrates to regulators that your organisation takes its obligations seriously.
Documenting your testing:
Consider the following actions (as they might apply to your operations):
Further reading: Testing the Design and Operating Effectiveness of Your Controls
An obligations register is a structured document that captures the specific legal and regulatory obligations that apply to your business under the AML/CTF Act and Rules, relevant Guidance issued by AUSTRAC, and the obligations set out in your own AML/CTF Program. It provides a clear, accessible reference for the AMLCO, management, and the board on what your organisation is required to do, and by when.
Without a well-maintained obligations register, it can be easy for obligations to be missed - particularly as the regulatory framework evolves, as AUSTRAC issues new guidance, or as your business changes in ways that bring new obligations into scope. An obligations register is not a static document: it needs to be reviewed and updated regularly.
What a well-structured obligations register should capture:
Board reporting obligations:
Rule 5-7 of the AML/CTF Rules requires the AMLCO to report to the board or governing body on: (a) compliance with AML/CTF policies; (b) whether those policies are appropriately managing ML/TF/PF risks; and (c) compliance with the Act, regulations and Rules. Capture this obligation in your register with a documented reporting cycle and evidence of each report.
Consider the following actions (as they might apply to your operations):
Further reading: Building a Compliance Obligations Register · Board Reporting, Obligations Registers and Controls Testing
A deep dive is a focused, in-depth review of a specific area of your AML/CTF Program.
Unlike a broad compliance assessment, a deep dive is deliberately narrow in scope. It may focus on a specific area of the Program - such as whether your transaction monitoring rules are calibrated correctly, or whether your staff are applying CDD procedures consistently - or on a key risk area, such as higher risk customers, high-volume channels, or a particular product or service. In either case, it goes further into the detail - examining data, testing samples, reviewing documentation, and interviewing staff - to form a well-evidenced view of whether that area is functioning as it should.
Areas you might conduct a deep dive (in no particular order of priority):
Consider the following actions (as they might apply to your operations):
A compliance check is a structured review of whether your AML/CTF Program meets the requirements of the AML/CTF Act and Rules, and whether it is being implemented effectively in practice. It goes beyond controls testing - it looks at the Program as a whole: its design, its documentation, its governance, and its operation.
What a compliance check might address:
A compliance check is distinct from a Program review. A Program review steps back and assesses the AML/CTF Program as a whole - whether its components are appropriately designed, properly documented, and working together coherently. A compliance check is narrower: it tests whether a specific obligation, policy, or process is being met in accordance with the applicable requirement. The two are complementary - a Program review will often identify areas warranting closer compliance checks, and patterns across compliance check findings will often point to issues a Program review should address. A Program review is also distinct from an independent evaluation - a Program review does not carry an independence requirement and can be conducted by a consultant or adviser who has helped you build or maintain your Program. The purpose of a Program review is to improve the Program; the purpose of an independent evaluation is to obtain an unbiased external view of whether it is adequate and compliant.
Consider the following actions (as they might apply to your operations):
Under the AML/CTF Act and Rules, reporting entities must provide AML/CTF training to their employees. Training must be ongoing and role-appropriate - a one-off induction module will not be sufficient. Entities should be able to demonstrate what training was provided, to whom, when, and that staff understood their obligations.
What your training program should cover:
Consider the following actions (as they might apply to your operations):
Further reading: AML/CTF Training - Things to Consider · Employee Due Diligence and AML/CTF Programs
Transaction monitoring is the process by which your organisation identifies transactions that may be indicative of money laundering, terrorism financing, or proliferation financing. It is a core component of your AML/CTF Program and a direct expression of your obligation to monitor the business relationship with your customers on an ongoing basis.
Transaction monitoring rules (sometimes called scenarios or typologies) are the specific parameters your system or process uses to flag transactions for review. A well-designed set of rules reflects your risk assessment - the rules you apply should be calibrated to the ML/TF/PF risks you have identified as relevant to your business, your customer base, and your designated services.
What effective transaction monitoring rules look like:
Consider the following actions (as they might apply to your operations):
Further reading: Transaction Monitoring for Pubs and Clubs · Pro Forma Matrix - Mapping TMP to Risk
Effective governance of an AML/CTF Program requires that the board and senior management receive regular, meaningful reporting on the state of the Program. Reporting is not a formality - it is the mechanism by which the board discharges its oversight obligations and by which management is held accountable for the Program's performance.
What board / senior management reporting should cover:
Governance charters:
A governance charter formalises the structure through which AML/CTF oversight is exercised. It defines who is responsible for what, how decisions are made, how issues are escalated, and how the board and management interact in relation to the Program. Without a charter, oversight arrangements tend to be informal and inconsistent - which makes it difficult to demonstrate to AUSTRAC that governance is functioning as required.
Consider the following actions (as they might apply to your operations):
Further reading: Board Reporting, Obligations Registers and Controls Testing
An independent evaluation is a formal assessment of your AML/CTF Program conducted by a person who is independent of the design and operation of the Program. The obligation to arrange an independent evaluation is set out in Rule 5-8 of the AML/CTF Rules.
Independence means the evaluator must not have been involved in designing or operating the Program being assessed. In practice, this means the evaluation is conducted by an external party - typically a specialist AML/CTF consultancy, law firm, or professional services firm - rather than by your internal compliance and risk function or the AMLCO.
What independence means in practice:
What an independent evaluation must assess:
Findings from the evaluation must be reported to the board or governing body. Critically, there is also an obligation to act on findings - identifying deficiencies is not sufficient; the entity must address them.
Frequency:
The Rules do not prescribe a fixed frequency. The obligation is to conduct an independent evaluation when the entity considers it appropriate, having regard to the nature, size, and complexity of the business and its risk profile. AUSTRAC can also direct an entity to arrange an independent evaluation. In practice, many entities build a regular evaluation cycle into their Program governance - the appropriate interval will depend on your risk profile, the complexity of your Program, and whether there have been material changes to your business or the regulatory environment.
Consider the following actions (as they might apply to your operations):
Further reading: Independent Review of Your AML/CTF Program
An AML/CTF Program is only as effective as the resources behind it. A well-designed Program that is under-resourced - whether in people, technology, or external support - will not operate as intended. Resourcing decisions are therefore a governance matter, not just an operational one, and the board and senior management are accountable for ensuring the Program has what it needs to function effectively.
People:
The people dimension of resourcing covers both headcount and capability. Having the right number of people is important, but having people with the right skills and experience is equally so. AML/CTF compliance is a specialist discipline - it requires an understanding of the regulatory framework, the business and its risk profile, and the practical realities of how controls operate on the ground.
Technology:
Technology is an enabler of an effective AML/CTF Program - but it is not a substitute for sound judgment, well-designed controls, or a capable compliance team. The right technology can significantly improve the efficiency and effectiveness of transaction monitoring, customer due diligence, and record-keeping. The wrong technology - or technology that is poorly configured or not maintained - can create a false sense of security and introduce new risks.
Operating models:
There is no single right operating model for AML/CTF compliance. The appropriate model depends on the size and complexity of the business, its risk profile, and the resources available. Common models include a fully in-house operations, compliance and risk function, a hybrid model that combines internal staff with external specialist support, and an outsourced model where some or all operations, compliance and risk functions are performed by a third party. Each has advantages and limitations.
Consider the following actions (as they might apply to your operations):
Lane Consulting & Advisory provides practical, hands-on support across all aspects of AML/CTF compliance - from risk appetite setting and risk assessments through to controls testing and independent review.