AML/CTF Support

Your AML/CTF Program

Before anything else, your business must be enrolled with AUSTRAC as a reporting entity. From there, an effective AML/CTF Program rests on a clearly articulated risk appetite, a documented methodology, and an enterprise-wide risk assessment that genuinely reflects the business. Controls must be tested and demonstrably operating as designed. Policies translate identified risks into procedures and controls. Appointing an AMLCO and Senior Manager with clear accountability is a legal requirement - and a governance foundation. An obligations register records what must be done, by whom, and when. Deep dives focus attention on areas of heightened risk. Compliance checks and Program reviews test whether the Program is operating as expected. Training equips staff to recognise and report suspicious activity. Transaction monitoring identifies activity warranting further scrutiny. Board and senior management reporting keeps those responsible for oversight informed and accountable. Independent evaluations provide an objective external view of whether the Program is fit for purpose. And underpinning all of this is resourcing - the people, technology, and operating model that give the Program the capacity to function effectively.

The sections below step through the key elements of an AML/CTF Program. This material is general in nature, is not exhaustive, is not legal advice, and is not a substitute for professional legal, risk or compliance advice tailored to your circumstances.

Need support building or reviewing your AML/CTF Program or any of the key components we outline above?

Get in touch

AUSTRAC Enrolment

Before you can build and operate an AML/CTF Program, you must first be enrolled with AUSTRAC as a reporting entity. Enrolment is the mechanism by which AUSTRAC identifies the businesses that are subject to the AML/CTF Act and Rules, and it is a legal obligation - not an optional step.

Australia's AML/CTF framework applies to businesses that provide one or more "designated services" as defined in the AML/CTF Act. If your business provides a designated service, you are a reporting entity and you must enrol with AUSTRAC. Operating as a reporting entity without being enrolled is a breach of the Act.

Tranche 1 and Tranche 2 - what is the difference?

Australia's AML/CTF framework has been extended in two tranches. Understanding which tranche applies to your business determines when your obligations commenced and what is required of you.

Tranche 1:

Tranche 1 covers the sectors that have been subject to Australia's AML/CTF framework since it was first introduced - broadly, financial services, gambling, bullion dealing, and certain remittance and digital currency exchange services. If your business falls within Tranche 1, your AML/CTF obligations have been in place for some time and full compliance is expected now.

  • Banks, credit unions, and other authorised deposit-taking institutions
  • Casinos and gaming machine operators
  • Bookmakers and wagering service providers
  • Remittance dealers and money transfer businesses
  • Digital currency exchange providers
  • Bullion dealers
  • Certain financial planners, stockbrokers, and other providers of financial services

Tranche 1 entities should also note that the reforms to the AML/CTF Act and Rules apply to them, and existing Programs will need to be reviewed against the new framework.

Tranche 2:

Tranche 2 extends the AML/CTF framework to a broader range of professional service providers - sectors that have historically been outside the regime but that are recognised internationally as presenting significant ML/TF/PF risk. The Tranche 2 reforms were enacted through the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 and the associated AML/CTF Rules 2025.

Tranche 2 entities include lawyers, accountants, real estate agents, trust and company service providers, and dealers in precious metals and stones. From 1 July 2026, these businesses are required to enrol with AUSTRAC, adopt an AML/CTF Program, conduct customer due diligence, and meet ongoing reporting and record-keeping obligations. A transitional period applies for some obligations - but enrolment and Program adoption are required from commencement on 1 July 2026.

  • Lawyers and law firms providing certain designated services (e.g. conveyancing, company formation, managing client funds)
  • Accountants and accounting firms providing certain designated services (e.g. managing client funds, company formation, tax advice in certain circumstances)
  • Real estate agents involved in buying and selling real property
  • Trust and company service providers
  • Dealers in precious metals and precious stones

The designated services that capture lawyers, accountants and other Tranche 2 entities are specific and technical. If your business is in any of the Tranche 2 sectors, you should obtain advice on whether the specific services you provide are captured - the categories above are indicative only.

Consider the following actions (as they might apply to your operations):

  • Confirming that your business is enrolled with AUSTRAC - if you are not enrolled and you provide a designated service, you are in breach of the Act
  • Reviewing the list of designated services in the AML/CTF Act to confirm which services your business provides and whether all of them are captured in your enrolment, then make sure these are captured in a separate tab of your EWRA
  • Updating your enrolment if your business has changed - for example, if you have added new services, changed your legal structure, or changed the nature of your operations
  • If you are a Tranche 2 entity, confirming that your enrolment has been completed and that you have adopted an AML/CTF Program - the transitional period does not defer the enrolment obligation
  • Retaining evidence of your enrolment and any updates to it as part of your AML/CTF records

The Importance of Setting Your Risk Appetite

Australia's AML/CTF framework is built on a risk-based approach. As AUSTRAC describes it, a risk-based approach means that the resources, effort, and scrutiny you apply are proportionate to the level of ML/TF/PF risk you face. Higher-risk customers, products, channels, and jurisdictions attract more rigorous controls and oversight; lower-risk areas can be managed with lighter-touch measures. This principle runs through every element of your Program - from how you assess risk, to how you design controls, to how you test them.

Your risk appetite is the foundation of your AML/CTF Program. It defines the level and type of money laundering, terrorism financing, and proliferation financing risk your organisation is willing to accept in pursuit of its objectives - and the level it is not.

A well-articulated risk appetite does more than satisfy a regulatory requirement. It drives every downstream decision in your Program: which customers you take on, which products you offer, which channels you operate through, and which jurisdictions you engage with. Without it, your risk assessments lack an anchor, your controls lack a rationale, and your board lacks a framework for oversight.

Risk appetite must be set at the board or governing body level. It should be documented, approved, and reviewed regularly - and it must be genuinely reflected in how your business operates. A risk appetite statement that is not embedded in decision-making is not a risk appetite.

Key elements of an effective risk appetite statement:

  • A clear articulation of the ML/TF/PF risks the organisation is and is not willing to accept
  • Alignment with the organisation's overall risk framework and strategic objectives
  • Specific thresholds or tolerances for key risk categories (customer, product, channel, jurisdiction)
  • Board or governing body sign-off and periodic review
  • Linkage to the enterprise-wide risk assessment and downstream controls

If your risk appetite has not been formally set, or has not been reviewed since your last risk assessment, that is a gap that needs to be addressed before the rest of your Program can be properly calibrated.

Consider the following actions (as they might apply to your operations):

Developing a formal Risk Appetite Statement for ML/TF/PF and/or update your broader business Risk Appetite Statement to address ML/TF/PF risks and your AML/CTF compliance risks.

Risk Assessment Methodologies

A risk assessment methodology (RAM) is the structured approach your organisation uses to identify, analyse, and evaluate ML/TF/PF risks. It determines how you measure risk, how you weight different risk factors, and how you arrive at an overall risk rating for your business.

There is no single prescribed methodology for an EWRA. What stakeholders - including your board, auditors, and regulators - will look for is an approach that is fit for purpose, documented, and defensible. In practice, methodology choices sit on two axes.

The first is how risk is rated:

  • Qualitative - risk is rated using descriptive categories such as low, medium, or high. Each category is defined so that ratings are applied consistently, and the assessment relies on the judgement of the people conducting it
  • Quantitative - risk is scored numerically against defined criteria, with each criterion weighted to reflect its relative importance. Despite the appearance of precision, the scores themselves are usually based on judgement rather than hard data
  • Hybrid - descriptive ratings supported by numeric scoring. We have seen the combination of a likelihood-and-consequence matrix with descriptor-based assessment. Likelihood (how probable an ML/TF/PF event is) and consequence (the severity if it occurs) are each scored on a defined scale, with the combination producing an overall risk rating via a matrix. In practice, this matrix sits behind two operational approaches: for discrete events such as typologies, likelihood and consequence are scored separately and read directly against the matrix; for broader risk factors such as customer or product risk, the two dimensions are pre-collapsed into composite descriptors that progress across a single scale, where each descriptor reflects a defined combination of likelihood and consequence. Both approaches draw on the same underlying matrix logic but apply it at different levels of granularity

The second is how risk is analysed and evidenced:

  • Typology and scenario analysis - working through known ML/TF/PF typologies that are relevant to your sector and business model to test whether your business is exposed, and if so, to what degree
  • Descriptor questionnaires - structured tools where the person completing the assessment selects the statement that best describes their business for each risk factor. Each option maps to a risk rating, which makes the process repeatable and consistent across different business units or venues
  • Control effectiveness assessment - looking at the controls you have in place to manage each risk, assessing whether they are well designed and actually working, and using that to arrive at a residual risk rating - that is, the risk that remains after your controls are taken into account

Most credible EWRAs combine elements from both axes. The choice of rating approach is less important than ensuring the methodology is applied consistently, the inputs are sourced, and the reasoning from input to rating is transparent.

Whichever methodology you adopt, it must address the four key risk categories required under the AML/CTF framework (AUSTRAC refers to these as 'factors'): customer risk, designated services risk, channel risk, and jurisdictional risk. Each category should be assessed individually and then brought together - consistently with your RAM - into an enterprise-wide view. For certain businesses that rely upon ACIP exemptions under Australia's AML laws, this may also involve a more detailed methodology on individual customer types.

For organisations that operate across multiple venues, branches, or outposts, your methodology should contemplate how risk is assessed at each location and how those assessments roll up into the enterprise-wide picture. A 'parent' risk assessment captures the overall risk profile of the organisation, while 'child' assessments address the specific risk profile of each venue or branch - reflecting differences in customer base, product mix, geographic location, and local operating environment. Where venues differ materially in their risk exposure, those differences must be reflected in the assessment rather than averaged away. A single enterprise-wide assessment that does not account for venue-level variation will not accurately represent the organisation's true risk profile.

Where your organisation applies weighting or averaging in your assessment, you may find that you need to make informed assumptions or compromises. This could elevate the possibility that higher risk issues are missed - make sure you address that risk by ensuring the appropriate elevation and actioning of issues in these scenarios.

Your methodology should also account for the inherent risk your business faces before controls are applied, and the residual risk that remains after controls are in place. This distinction is critical - it is what allows you to assess whether your controls are adequate, and where gaps exist.

Selecting the right methodology:

The right methodology for your organisation depends on its size, complexity, and the nature of its ML/TF/PF risk exposure. A small, low-complexity business may be well-served by a straightforward qualitative approach. A large, multi-product, multi-jurisdiction business will likely require a more sophisticated framework.

What matters most is that your methodology is applied consistently, documented clearly, and produces a risk assessment that your board and senior management can stand behind.

Consider the following actions (as they might apply to your operations):

Developing a detailed Risk Assessment Methodology that sets out how you identify, assess, rate, weight and treat ML/TF/PF risks presented by your customers, designated services, channels and jurisdictions. You might also consider including in your methodology how you look at other relevant risks related to your employees, your location, third parties in your ecosystem and the threat environment.

Documenting Your Enterprise-Wide Risk Assessment

Your enterprise-wide risk assessment (EWRA) is the central document of your AML/CTF Program. It brings together your assessment of customer, designated service, channel, and jurisdictional risk (as well as the other risks you have identified in your methodology relevant to your business) into a single, coherent view of your organisation's overall ML/TF/PF risk exposure.

The EWRA should follow your chosen methodology. That means the risk ratings, weightings, and conclusions in your assessment should flow logically from the methodology you have documented and adopted.

What a well-documented EWRA should include:

  • An executive summary suitable for board review and sign-off
  • A description of the methodology applied, including how risk factors are identified, weighted, and aggregated
  • Details about your organisation's context - including, without limitation, what its purpose is, its structure, what it does, who it provides services to, how and where it operates, along with details about its size, scale and complexity
  • Assessment of each risk factor: customer, designated service, channel, and jurisdiction
  • Assessment of relevant typologies, red flags and risk indicators by factor
  • Identification of inherent risk before controls, and residual risk after controls
  • A clear overall risk rating for the organisation
  • Identification of key risk drivers and areas of elevated exposure
  • Linkage to the controls and mitigation measures in place
  • Identification of gaps or areas requiring further action
  • Date of assessment, version control, and sign-off by appropriate personnel

The EWRA is not a static document. It must be reviewed and updated whenever there is a material change to your business - new designated services, new customer segments, new channels, new jurisdictions, or changes in the regulatory or threat environment. It should be reviewed regularly, informed by your context (the nature of your business, its size and complexity).

Critically, the EWRA must be owned. Someone in your organisation - typically the AML/CTF Compliance Officer (AMLCO) - must be accountable for keeping it current, ensuring it reflects the business as it actually operates, and escalating material changes to the board.

Consider the following actions (as they might apply to your operations):

Compiling your EWRA in a workbook, with separate tabs for each key risk factor area that you assess. Make sure you have a tab that summarises the overarching inherent and residual ML/TF/PF risks. Think of it like your assessor is "following the bouncing ball" as set out in your RAM. Ensure that you clearly link the inherent risks to the controls you have in place to mitigate/manage those risks and document how you have assured yourself that the controls are operating to mitigate the risk. Collate your controls together in a readily accessible library and make sure you have links to each control you have identified for quick access and independent evaluation purposes.

What we expect you will find is that for some organisations, this is a hefty workbook. Technology can be your friend in capturing your assessment - explore your options!

Further reading: Gaming - Customer Risk Assessments · Gaming - Product Risk Assessments · Gaming - Channel Risk Assessments · The Risk Assessment Process - A Diagram

AML/CTF Policies and Program

Your AML/CTF Program must include AML/CTF policies - the documented rules, procedures, and standards that govern how your organisation identifies, manages, and mitigates its ML/TF/PF risks. Policies are a significant part of the operational expression of your Program: they translate your risk assessment and risk appetite into day-to-day practice.

Under the AML/CTF Act and Rules, your policies must be appropriate to the nature, size, and complexity of your business and the ML/TF/PF risks you face. They must be kept up to date, and staff must be trained on them.

What your AML/CTF policies should cover:

  • ML/TF/PF risk assessment - how your organisation identifies, assesses, and manages its ML/TF/PF risks, including the methodology applied and the frequency of review
  • Customer identification and verification - how you identify and verify customers, including the documents and data sources you rely on, and how you handle customers who cannot be verified
  • Beneficial ownership - how you identify and verify the beneficial owners of customers that are not natural persons
  • Customer due diligence - your standard, simplified, and enhanced due diligence procedures, and the triggers for each
  • Ongoing customer due diligence - how you monitor customer relationships and transactions on an ongoing basis, and when you re-verify or update customer information
  • Politically exposed persons (PEPs) - how you identify and manage PEP relationships, including the enhanced due diligence measures applied. A PEP is an individual who holds, or has held, a prominent public position or function - such as a head of state, senior government official, senior military officer, senior executive of a state-owned enterprise, or senior official of a political party. The term also extends to immediate family members and close associates of such individuals. PEPs present a higher ML/TF risk because their position may give them access to public funds or the ability to influence decisions in ways that can be exploited for corrupt purposes. This does not mean all PEPs are corrupt - it means they require enhanced scrutiny
  • Transaction monitoring - how you monitor transactions for unusual or suspicious activity, including the rules and thresholds you apply
  • Suspicious matter reporting - how you identify, escalate, assess, and report suspicious matters (SMRs) to AUSTRAC, including tipping-off obligations
  • Threshold transaction reporting - how you identify and report threshold transactions involving physical currency of $10,000 or more
  • International funds transfer reporting - how you identify and report international funds transfers
  • Sanctions screening - how you screen customers and transactions against applicable sanctions lists
  • Record keeping - what records you keep, for how long, and how they are stored and accessed
  • Staff training - how you ensure staff are trained on their AML/CTF obligations, and how training is recorded
  • Employee due diligence - how you screen employees and contractors in AML/CTF-sensitive roles
  • Governance and oversight - the roles and responsibilities of the AMLCO, management, and the board in relation to the Program, including the AMLCO's reporting obligations
  • Reliance on third parties and outsourcing - where applicable, your procedures for managing designated business group arrangements, outsourced functions, and third-party reliance
  • New and developing technologies - how you identify and manage ML/TF/PF risks arising from new or developing technologies, products, or delivery channels before they are introduced
  • Non-face-to-face transactions - how you manage the additional ML/TF/PF risks associated with customers and transactions that are not conducted in person
  • Program review - how and when your AML/CTF Program will be reviewed, by whom, and how findings will be reported to the board and actioned

Consider the following actions (as they might apply to your operations):

  • Reviewing your policies against your risk assessment - do your policies address the risks you have identified? Create a tab on your EWRA Workbook that maps the identified risks and the controls to your AML/CTF Policies
  • Ensuring each policy has a named owner, a review date, and version control
  • Testing whether your policies reflect actual practice - walk through a transaction or a customer onboarding with a staff member and compare what happens to what the policy says (see the Controls Monitoring and Testing section for more detail)
  • Keeping a policy register that lists all AML/CTF policies, their owners, and their last review dates
  • Engaging a law firm with specialist AML/CTF expertise to review your policies - they can be particularly helpful in ensuring your policies meet the requirements of the AML/CTF Act, Rules and relevant AUSTRAC guidance, and in identifying gaps that may not be apparent from an internal review alone

Appoint an AMLCO and Senior Manager

The AML/CTF Act and Rules require reporting entities to designate two key roles: an AML/CTF Compliance Officer (AMLCO) and a Senior Manager with responsibility for AML/CTF compliance. These are distinct roles with different functions, and both are required.

The AMLCO:

The AMLCO is responsible for the day-to-day management of the AML/CTF Program. The AMLCO is the person who owns the Program operationally - ensuring it is kept current, that controls are operating as designed, that staff are trained, that suspicious matters are identified and reported, and that the board and senior management are kept informed. In smaller organisations, the AMLCO may perform many of these functions directly. In larger organisations, the AMLCO may oversee a team. Either way, the operational accountability sits with the AMLCO.

  • Day-to-day management of the AML/CTF Program, including ensuring policies and procedures are current and being followed
  • Overseeing the identification, escalation, and reporting of suspicious matters to AUSTRAC
  • Ensuring staff training is delivered, recorded, and kept up to date
  • Monitoring and testing controls, and escalating failures or gaps to management and the board
  • Keeping the EWRA current and ensuring it reflects the business as it actually operates
  • Reporting to the board and senior management on the performance of the Program, including key metrics, issues, and remediation progress
  • Liaising with AUSTRAC, including managing any regulatory engagement or requests for information
  • Keeping abreast of changes to the AML/CTF Act, Rules, and AUSTRAC guidance, and ensuring the Program is updated accordingly

The Senior Manager:

The Senior Manager is a member of senior management who is accountable for AML/CTF compliance at the governance level. Where the AMLCO is responsible for how the Program operates day-to-day, the Senior Manager is responsible for ensuring that the Program has the organisational support, resources, and authority it needs to function effectively - and for escalating material AML/CTF issues to the board.

The Senior Manager does not manage the Program operationally - that is the AMLCO's role. The Senior Manager provides the governance layer above the AMLCO: championing the Program at the executive level, ensuring it receives adequate resourcing, and holding the organisation accountable for addressing identified deficiencies. In practice, the Senior Manager is often a Chief Risk Officer, Chief Compliance Officer, Chief Executive Officer, or equivalent - someone with sufficient seniority and authority to drive action across the business.

How the two roles interact:

The AMLCO and Senior Manager are complementary. The AMLCO runs the Program; the Senior Manager ensures the Program has what it needs to run effectively and that the board is appropriately engaged. The AMLCO typically reports to or through the Senior Manager on AML/CTF matters, and the Senior Manager is the conduit between the compliance and risk function and the board. Where the AMLCO identifies a material issue that requires board attention or additional resources, it is the Senior Manager's role to ensure that escalation happens and that it is acted upon.

Who can hold these roles:

The AML/CTF Rules do not prescribe specific qualifications for either role, but both must have sufficient authority, seniority, and competence to perform their respective functions effectively. The AMLCO must have a genuine understanding of the business and its ML/TF/PF risks and the ability to escalate issues and drive remediation. The Senior Manager must have sufficient seniority to hold the organisation accountable and sufficient access to the board to discharge their governance responsibilities. In some smaller organisations, the same person may hold both roles - but care should be taken to ensure that the governance and operational functions are still being performed distinctly.

Consider the following actions (as they might apply to your operations):

  • Ensuring both the AMLCO and Senior Manager appointments are documented and approved at the board or governing body level
  • Defining both roles, their responsibilities, and their reporting lines clearly in your AML/CTF policies
  • Ensuring the AMLCO has a direct reporting line to the Senior Manager on AML/CTF matters, and that the Senior Manager has a direct reporting line to the board or a board committee
  • Providing the AMLCO with adequate resources, including access to specialist external advice where needed - the Senior Manager should be the advocate for this at the executive level
  • Having a documented succession plan or acting arrangement for both roles so that responsibilities are covered during absences or transitions
  • Reviewing both appointments when there are material changes to the business, the risk profile, or the regulatory environment

Further reading: Stepping Into the AMLCO Role

Controls Monitoring and Testing

Controls monitoring and testing are distinct but complementary activities. Monitoring is the ongoing, day-to-day oversight of whether controls are operating as intended. Testing is the periodic, structured assessment of whether controls are designed appropriately and are effective in practice. Both are essential to a well-functioning AML/CTF Program.

Before you can monitor or test a control, it needs to be properly documented. A well-documented control has six key attributes.

  • Purpose (or control objective) - what ML/TF/PF risk does the control address, and what outcome is it designed to achieve? Without a clear purpose, the control cannot be monitored or tested for effectiveness because there is no benchmark for "working"
  • Owner (accountability) - the named role responsible for the control operating as designed. Not "the venue" or "compliance" - a position. Owner does not mean operator: a control can be operated by floor staff but owned by the AMLCO or Duty Manager. The control owner should also be actively monitoring to ensure that the control they are responsible for is operating effectively
  • Type - whether the control is preventative (stops the risk from materialising, e.g. ID verification), detective (identifies the risk after it has manifested, e.g. transaction monitoring rules, daily exception reports), or corrective (remediates after detection, e.g. suspicious matter report (SMR) submission, customer exit procedures). Effective Programs need a mix - a controls register weighted entirely to detective controls is a red flag
  • Frequency (or timing) - when and how often the control operates: real-time, daily, per-transaction, monthly, or on a trigger event. "Ad hoc" can be indicative of a potential defect
  • Mode - how the control operates: manual, automated, or hybrid. Manual controls carry higher residual risk because they depend on human consistency. Automated controls carry lower residual risk but require initial design validation and ongoing rule-tuning
  • Evidence (auditability) - how the operation of the control is recorded and what an independent reviewer can inspect to monitor or test it. Without evidence, the control is unprovable and effectively does not exist for assurance purposes. This is where many controls registers fall over on independent evaluation

Who monitors controls - and how:

  • AMLCO - the AMLCO is the primary owner of controls monitoring. This includes reviewing exception reports, transaction monitoring alerts, and escalations from staff; tracking the status of open issues and remediation actions; and maintaining oversight of whether controls are operating consistently across the business. The AMLCO should be reporting regularly to management on the health of the Program.
  • Control owners - each control owner is responsible for monitoring the control they own to ensure it is operating effectively. This means actively checking that the control is functioning as designed, identifying any failures or gaps, and escalating issues to the AMLCO.
  • Management - management monitors controls through the reporting they receive from the AMLCO, and through their own operational oversight. This includes reviewing management information on suspicious matter reports, threshold transaction reports, customer due diligence completion rates, and training compliance. Management is responsible for ensuring that resourcing, systems, and processes support the controls that are in place.
  • Board - the board monitors controls at a governance level. This means receiving regular, meaningful reporting from management and the AMLCO on the state of the Program - not just a status update, but substantive information about whether controls are working, where gaps exist, and what is being done about them. Board sign-off on the risk assessment and Program is not a one-time event: it requires ongoing engagement with how the Program is performing.

Controls Testing:

What controls testing can involve:

  • Design effectiveness testing - assessing whether controls are designed appropriately to address the risks they are intended to mitigate
  • Operating effectiveness testing - assessing whether controls are actually functioning as designed in practice
  • Transaction testing - reviewing samples of transactions to verify that monitoring and reporting controls are working
  • Customer due diligence (CDD) testing - reviewing samples of customer files to verify that know your customer (KYC) and CDD processes are being followed
  • System testing - verifying that automated monitoring systems are generating alerts as expected and that alerts are being actioned
  • Training effectiveness testing - assessing whether staff understand their obligations and can apply them in practice

Controls testing should be risk-based - meaning the frequency and rigour of testing is proportionate to the level of risk the control is designed to address. Higher-risk areas of your Program warrant more frequent and more rigorous testing. The results of testing must be documented, and any failures or gaps must be escalated and remediated.

Independent vs internal testing:

Controls testing can be conducted internally - by your compliance and risk function or internal audit - or independently, by an external party. Both have a role. Internal testing provides ongoing assurance and allows issues to be identified and addressed quickly. Independent testing provides an objective assessment that is not subject to the same conflicts of interest as internal review.

In some cases, independent testing is not optional. Regulators may require it as part of a remediation program, or as a condition of a licence. Even where it is not required, periodic independent testing is good practice - and demonstrates to regulators that your organisation takes its obligations seriously.

Documenting your testing:

  • A testing plan that identifies which controls will be tested, when, and by whom
  • Testing workpapers that document the methodology, sample selection, and findings
  • A summary of results, including any failures, gaps, or areas of concern
  • An action plan for remediating identified issues, with owners and timeframes
  • Evidence of escalation to senior management and the board
  • Sign-off by the AMLCO and, where appropriate, the board

Consider the following actions (as they might apply to your operations):

  • Documenting your assurance framework - setting out how monitoring and testing activities are planned, conducted, recorded, and reported across the organisation
  • Documenting key risk and compliance indicators based on available data to report on the effectiveness of your controls and the status of your risks
  • Introducing technology to assist you in driving a consistent approach in your assurance environment

Further reading: Testing the Design and Operating Effectiveness of Your Controls

Obligations Registers

An obligations register is a structured document that captures the specific legal and regulatory obligations that apply to your business under the AML/CTF Act and Rules, relevant Guidance issued by AUSTRAC, and the obligations set out in your own AML/CTF Program. It provides a clear, accessible reference for the AMLCO, management, and the board on what your organisation is required to do, and by when.

Without a well-maintained obligations register, it can be easy for obligations to be missed - particularly as the regulatory framework evolves, as AUSTRAC issues new guidance, or as your business changes in ways that bring new obligations into scope. An obligations register is not a static document: it needs to be reviewed and updated regularly.

What a well-structured obligations register should capture:

  • The specific obligation - described clearly and in plain language
  • The source of the obligation - the relevant section of the AML/CTF Act, the AML/CTF Rules, relevant AUSTRAC guidance, or the section of your AML/CTF Program where it is documented
  • The owner - the role responsible for ensuring the obligation is met
  • How the obligation is met - the control, process, or procedure that gives effect to it
  • The frequency or trigger - when the obligation applies (ongoing, periodic, event-triggered)
  • The status - whether the obligation is currently being met, and any known gaps or issues
  • Evidence - how compliance with the obligation is recorded and can be demonstrated (e.g. do you have a metric that can evidence compliance with the requirement?)

Board reporting obligations:

Rule 5-7 of the AML/CTF Rules requires the AMLCO to report to the board or governing body on: (a) compliance with AML/CTF policies; (b) whether those policies are appropriately managing ML/TF/PF risks; and (c) compliance with the Act, regulations and Rules. Capture this obligation in your register with a documented reporting cycle and evidence of each report.

Consider the following actions (as they might apply to your operations):

  • Building your obligations register from the AML/CTF Act and Rules directly - do not rely solely on summaries or guidance materials, which may not capture every applicable obligation
  • Reviewing your obligations register whenever there is a change to the legislation, new AUSTRAC guidance is issued, or your business changes in a way that may bring new obligations into scope
  • Using your obligations register as a foundation for your compliance assessment - it provides the framework against which compliance is measured
  • Ensuring the AMLCO board reporting obligation under Rule 5-7 of the AML/CTF Rules is documented, scheduled, and evidenced each cycle

Further reading: Building a Compliance Obligations Register · Board Reporting, Obligations Registers and Controls Testing

Deep Dives

A deep dive is a focused, in-depth review of a specific area of your AML/CTF Program.

Unlike a broad compliance assessment, a deep dive is deliberately narrow in scope. It may focus on a specific area of the Program - such as whether your transaction monitoring rules are calibrated correctly, or whether your staff are applying CDD procedures consistently - or on a key risk area, such as higher risk customers, high-volume channels, or a particular product or service. In either case, it goes further into the detail - examining data, testing samples, reviewing documentation, and interviewing staff - to form a well-evidenced view of whether that area is functioning as it should.

Areas you might conduct a deep dive (in no particular order of priority):

  • Customer due diligence - are KYC processes being applied consistently, and is the documentation adequate?
  • Transaction monitoring - are rules appropriately calibrated, are alerts being actioned in a timely way, and is the rationale for closing alerts documented?
  • Suspicious matter reporting - are SMRs being identified and submitted correctly, and is the decision-making process documented?
  • High-risk customers - are enhanced due diligence obligations being met, and is ongoing monitoring adequate?
  • Enhanced due diligence (EDD) on high-risk customers - is EDD being triggered at the right points, are the measures applied proportionate to the risk, and is the documentation sufficient to demonstrate that the obligation has been met?
  • Third-party reliance - where your business relies on a third party to perform CDD or other AML/CTF functions, is that reliance appropriately documented, are the contractual arrangements in place, and are you satisfied the third party is meeting the required standard?
  • Technology change - where a new system, platform, or tool has been introduced that affects how AML/CTF controls operate, has the impact on your Program been assessed and have controls been updated accordingly?
  • Source of funds and source of wealth verification - are these being obtained and verified in the right circumstances, is the standard of verification adequate, and is the documentation retained?
  • A specific product, channel, or customer segment that has been identified as elevated risk

Consider the following actions (as they might apply to your operations):

  • Conducting a deep dive when a compliance check flags a concern that requires further investigation before you can form a confident view
  • Using deep dives proactively - particularly in areas of your Program that carry higher inherent risk or that have not been closely examined in recent cycles - for instance, you might conduct deep dives on the highest risk rated factors in your EWRA
  • Ensuring that deep dive findings are documented, reported to management and the board, and that any remediation actions are tracked through to completion
  • Engaging an independent reviewer (like a law or professional services firm specialised in AML/CTF) to conduct deep dives where objectivity is important or where internal capacity is limited

Compliance Checks and Program Reviews

A compliance check is a structured review of whether your AML/CTF Program meets the requirements of the AML/CTF Act and Rules, and whether it is being implemented effectively in practice. It goes beyond controls testing - it looks at the Program as a whole: its design, its documentation, its governance, and its operation.

What a compliance check might address:

  • Whether the AML/CTF Program is appropriately documented and up to date
  • Whether the risk assessment reflects the current state of the business
  • Whether the risk appetite has been formally set and is reflected in the Program
  • Whether customer due diligence (CDD) processes are operating as designed
  • Whether transaction monitoring rules are calibrated appropriately and alerts are being actioned
  • Whether threshold transaction reporting, international funds transfer reporting and suspicious matter reporting obligations are being met
  • Whether staff training is current, role-appropriate, and documented
  • Whether governance arrangements - including board and management oversight - are functioning effectively
  • Whether identified issues are being escalated, tracked, and remediated

A compliance check is distinct from a Program review. A Program review steps back and assesses the AML/CTF Program as a whole - whether its components are appropriately designed, properly documented, and working together coherently. A compliance check is narrower: it tests whether a specific obligation, policy, or process is being met in accordance with the applicable requirement. The two are complementary - a Program review will often identify areas warranting closer compliance checks, and patterns across compliance check findings will often point to issues a Program review should address. A Program review is also distinct from an independent evaluation - a Program review does not carry an independence requirement and can be conducted by a consultant or adviser who has helped you build or maintain your Program. The purpose of a Program review is to improve the Program; the purpose of an independent evaluation is to obtain an unbiased external view of whether it is adequate and compliant.

Consider the following actions (as they might apply to your operations):

  • Conducting a compliance check on a regular cycle - the frequency should be informed by your risk profile, the complexity of your Program, and any material changes to your business or the regulatory environment
  • Using the results of your compliance check to update your risk assessment, your controls register, and your Program documentation
  • Ensuring that the board receives a summary of compliance check findings and is sighted on any material gaps or remediation actions
  • Engaging an independent third party to conduct or peer-review your compliance check where internal resources or objectivity may be limited
  • If you are conducting compliance checks across multiple areas, consider engaging an external law firm or professional services firm to look at your Program as a whole from a compliance perspective - this is distinct from a targeted compliance check and closer to a Program review or independent evaluation

Training

Under the AML/CTF Act and Rules, reporting entities must provide AML/CTF training to their employees. Training must be ongoing and role-appropriate - a one-off induction module will not be sufficient. Entities should be able to demonstrate what training was provided, to whom, when, and that staff understood their obligations.

What your training program should cover:

  • The nature of ML/TF/PF risks and why they matter to your business
  • Your organisation's AML/CTF obligations under the Act and Rules
  • How to identify and escalate suspicious activity
  • Your organisation's AML/CTF policies and procedures, and how to apply them in practice
  • The consequences of non-compliance - for the organisation and for individuals
  • Role-specific obligations - for example, customer-facing staff need to understand CDD requirements in detail; management need to understand their oversight responsibilities; the board needs to understand its governance obligations

Consider the following actions (as they might apply to your operations):

  • Maintaining a training register that records who has completed training, when, and what version of the training they completed
  • Setting a training cycle - at minimum annually, and triggered by material changes to the Program, the legislation, or AUSTRAC guidance
  • Tailoring training content to the role - front-line staff, compliance staff, management, and the board each have different obligations and different risk exposures
  • Including scenario-based content that helps staff recognise suspicious activity in the context of your specific business and customer base - make sure that you train your staff on those typologies, red flags or indicators that you have rated at a higher inherent risk, so your staff know what to look for and how to report it to you if they see it
  • Consider adding a tab in your EWRA where you map your highest risk scenarios to where this is addressed in your training modules
  • Testing comprehension, not just completion - a short assessment at the end of each training module provides evidence that staff have understood the content
  • Retaining training materials as part of your records - if AUSTRAC asks what training was provided and when, you need to be able to show them

Further reading: AML/CTF Training - Things to Consider · Employee Due Diligence and AML/CTF Programs

Transaction Monitoring

Transaction monitoring is the process by which your organisation identifies transactions that may be indicative of money laundering, terrorism financing, or proliferation financing. It is a core component of your AML/CTF Program and a direct expression of your obligation to monitor the business relationship with your customers on an ongoing basis.

Transaction monitoring rules (sometimes called scenarios or typologies) are the specific parameters your system or process uses to flag transactions for review. A well-designed set of rules reflects your risk assessment - the rules you apply should be calibrated to the ML/TF/PF risks you have identified as relevant to your business, your customer base, and your designated services.

What effective transaction monitoring rules look like:

  • Rules are documented - each rule has a name, a description of what it is designed to detect, the parameters applied, and the rationale for those parameters
  • Rules are risk-based - the scenarios applied reflect the specific ML/TF/PF risks identified in your EWRA, not a generic library of rules that has never been reviewed against your risk profile
  • Rules are calibrated - thresholds and parameters have been set deliberately, with reference to your customer base and transaction patterns, and are reviewed periodically to ensure they remain appropriate
  • Alert volumes are manageable - your rules should be targeted to the specific risks in your EWRA, not cast so widely that they catch everything and mean nothing. Rules that are too broad generate high volumes of false positives, which creates alert fatigue and increases the risk that genuinely suspicious activity is missed. If your team cannot action alerts in a timely way, that is a signal that the rules need to be recalibrated - tightened in scope, better parameterised, or reduced in number - so that the alerts you do receive are meaningful and can be properly investigated
  • Alerts are actioned and documented - every alert should be reviewed, and the outcome of that review should be documented, including the rationale for closing the alert without further action
  • Rules are reviewed regularly - transaction monitoring rules should be reviewed at least annually, and whenever there is a material change to your business, your customer base, or the regulatory environment

Consider the following actions (as they might apply to your operations):

  • Mapping each of your transaction monitoring rules to the specific risk(s) in your EWRA that the rule is designed to detect - this demonstrates that your monitoring is risk-based and provides a clear audit trail
  • Consider adding a tab on your EWRA where you map your highest risks to the rules in your transaction monitoring program (TMP)
  • Conducting a tuning exercise periodically to review alert volumes, false positive rates, and whether rules are generating actionable alerts
  • Documenting your alert management process - who reviews alerts, within what timeframe, what the escalation path is, and how outcomes are recorded
  • Ensuring that your transaction monitoring coverage extends to all designated services and all customer segments identified as higher risk in your EWRA
  • Reviewing your rules whenever AUSTRAC publishes new typologies or guidance relevant to your sector

Further reading: Transaction Monitoring for Pubs and Clubs · Pro Forma Matrix - Mapping TMP to Risk

Board / Senior Management Reporting

Effective governance of an AML/CTF Program requires that the board and senior management receive regular, meaningful reporting on the state of the Program. Reporting is not a formality - it is the mechanism by which the board discharges its oversight obligations and by which management is held accountable for the Program's performance.

What board / senior management reporting should cover:

  • The current state of the AML/CTF Program - whether it is operating as designed and whether there are any material gaps or deficiencies
  • Risk profile - whether the organisation's ML/TF/PF risk exposure has changed since the last report, and whether the risk assessment remains current
  • Compliance with key obligations - threshold transaction reporting, suspicious matter reporting, international funds transfer reporting, and customer due diligence
  • Controls performance - whether controls are operating effectively, including any failures, gaps, or areas of concern identified through monitoring or testing
  • Regulatory developments - any changes to the AML/CTF Act, Rules, or AUSTRAC guidance that are relevant to the Program
  • Issues and remediation - a summary of issues identified since the last report, the status of remediation actions, and any issues that remain open beyond their target resolution date
  • Training compliance - whether staff training is current and whether any gaps have been identified
  • Transaction monitoring - alert volumes, alert outcomes, and any trends or patterns of note
  • Upcoming obligations - any reporting deadlines, review cycles, or regulatory engagements on the horizon

Governance charters:

A governance charter formalises the structure through which AML/CTF oversight is exercised. It defines who is responsible for what, how decisions are made, how issues are escalated, and how the board and management interact in relation to the Program. Without a charter, oversight arrangements tend to be informal and inconsistent - which makes it difficult to demonstrate to AUSTRAC that governance is functioning as required.

  • A board-level AML/CTF charter should set out the board's oversight responsibilities, the frequency and format of reporting it expects to receive, the matters reserved for board decision, and the escalation path for material issues
  • A management-level charter or terms of reference for any AML/CTF committee should define membership, quorum, meeting frequency, decision-making authority, and how minutes and actions are recorded and tracked
  • Charters should be reviewed and reapproved at least annually, and updated whenever there is a material change to the governance structure or the Program

Consider the following actions (as they might apply to your operations):

  • Putting in place a board-level AML/CTF charter and, where applicable, a management committee charter or terms of reference - these documents are evidence of active governance and are likely to be requested in any regulatory engagement
  • Developing a standard reporting template that covers the key areas above and is updated each reporting cycle - consistency makes it easier for the board to identify trends and changes over time
  • Including key metrics in your reporting - quantitative data on alert volumes, SMR numbers, training completion rates, and open issues gives the board a clearer picture than narrative alone
  • Ensuring that the AMLCO presents the report to the board directly, rather than it being tabled without discussion - direct engagement allows the board to ask questions and demonstrates active governance
  • Retaining copies of all reports provided to the board and senior management, together with evidence that they were received and considered - this is part of your record-keeping obligations

Further reading: Board Reporting, Obligations Registers and Controls Testing

Independent Evaluations

An independent evaluation is a formal assessment of your AML/CTF Program conducted by a person who is independent of the design and operation of the Program. The obligation to arrange an independent evaluation is set out in Rule 5-8 of the AML/CTF Rules.

Independence means the evaluator must not have been involved in designing or operating the Program being assessed. In practice, this means the evaluation is conducted by an external party - typically a specialist AML/CTF consultancy, law firm, or professional services firm - rather than by your internal compliance and risk function or the AMLCO.

What independence means in practice:

  • The evaluator must not have designed, built, or operated any part of the Program being assessed - this includes having written the policies, designed the controls, or provided ongoing compliance advice that shaped how the Program operates
  • An external consultant who has been embedded in your compliance and risk function, or who has provided the advice that underpins your Program, is not independent for the purposes of evaluating that Program - even if they are not an employee
  • Independence is assessed at the level of the specific Program being evaluated, not at the level of the organisation - a firm that has assisted with one aspect of your Program may still be independent for the purposes of evaluating a different aspect, but care should be taken
  • The evaluator should have no financial or other interest in the outcome of the evaluation - the engagement should be structured so that the evaluator is incentivised to give an honest assessment, not a favourable one
  • Where there is any doubt about independence, it is prudent to document the basis on which you have concluded the evaluator is independent. Ask the independent evaluator to explain how they meet your independence test as part of your scope

What an independent evaluation must assess:

  • Whether the Program complies with the AML/CTF Act and Rules
  • Whether the Program is adequate to manage the ML/TF/PF risks faced by the reporting entity

Findings from the evaluation must be reported to the board or governing body. Critically, there is also an obligation to act on findings - identifying deficiencies is not sufficient; the entity must address them.

Frequency:

The Rules do not prescribe a fixed frequency. The obligation is to conduct an independent evaluation when the entity considers it appropriate, having regard to the nature, size, and complexity of the business and its risk profile. AUSTRAC can also direct an entity to arrange an independent evaluation. In practice, many entities build a regular evaluation cycle into their Program governance - the appropriate interval will depend on your risk profile, the complexity of your Program, and whether there have been material changes to your business or the regulatory environment.

Consider the following actions (as they might apply to your operations):

  • Defining the scope of the evaluation clearly upfront, and ensuring the evaluator has access to all relevant documentation, data, and personnel
  • Treating the evaluation report as a board-level document - findings should be reported directly to the board, not filtered through management
  • Tracking remediation actions arising from the evaluation at the board level, with regular reporting on progress until all findings are closed
  • Commissioning an independent evaluation following a material regulatory change, a significant change to your business model, or any engagement with AUSTRAC that raises questions about the adequacy of your Program
  • Using the evaluation as a trigger for a broader Program refresh - an external reviewer will often surface issues that internal reviews have missed or normalised over time

Further reading: Independent Review of Your AML/CTF Program

Resourcing

An AML/CTF Program is only as effective as the resources behind it. A well-designed Program that is under-resourced - whether in people, technology, or external support - will not operate as intended. Resourcing decisions are therefore a governance matter, not just an operational one, and the board and senior management are accountable for ensuring the Program has what it needs to function effectively.

People:

The people dimension of resourcing covers both headcount and capability. Having the right number of people is important, but having people with the right skills and experience is equally so. AML/CTF compliance is a specialist discipline - it requires an understanding of the regulatory framework, the business and its risk profile, and the practical realities of how controls operate on the ground.

  • The AMLCO must have sufficient time to perform the role effectively - an AMLCO who is also carrying a full operational workload may not be able to give the Program the attention it requires. In smaller organisations where the AMLCO inevitably carries other responsibilities, the resourcing question becomes one of protected time, clear delegation, and access to specialist support
  • Where the compliance and risk function is small, consider whether specialist external support is needed to supplement internal capability - for example, for complex investigations, regulatory engagement, or independent review
  • Staff who perform AML/CTF functions (customer due diligence, transaction monitoring, suspicious matter reporting) must be adequately trained and supervised - capability gaps in the operational team translate directly into Program failures
  • Succession planning matters - if the AMLCO or a key compliance team member leaves, the Program should not be left without coverage; document role responsibilities and maintain institutional knowledge
  • As the business grows or its risk profile changes, the resourcing of the compliance and risk function should be reviewed - a Program that was adequately resourced two years ago may not be today. One framework for thinking about resourcing is the three lines of defence model - First Line (business and operations, who own and manage risk), Second Line (risk and compliance, who oversee and challenge), and Third Line (internal audit, who provide independent assurance). This is one lens among several, and is not compulsory - it may suit a large business but not a single-site operator. The right operating model depends on your context

Technology:

Technology is an enabler of an effective AML/CTF Program - but it is not a substitute for sound judgment, well-designed controls, or a capable compliance team. The right technology can significantly improve the efficiency and effectiveness of transaction monitoring, customer due diligence, and record-keeping. The wrong technology - or technology that is poorly configured or not maintained - can create a false sense of security and introduce new risks.

  • Transaction monitoring systems must be configured to reflect your specific risk profile - out-of-the-box rule sets are a starting point, not a finished product; rules must be calibrated to your business and reviewed regularly
  • Customer due diligence and onboarding platforms should support your CDD and KYC obligations, including the ability to apply different levels of due diligence based on risk rating
  • Case management systems for suspicious matter investigations should enable you to document the decision-making process clearly - the rationale for filing or not filing an SMR must be recorded and retained
  • Record-keeping systems must meet the retention requirements under the AML/CTF Act - records must generally be retained for seven years and be retrievable in a timely way
  • Where you rely on third-party technology providers for AML/CTF functions, you remain responsible for the adequacy of those functions - vendor due diligence and contractual protections are part of your Program
  • Technology changes - new systems, upgrades, or changes to configuration - should be assessed for their impact on AML/CTF controls before they are implemented

Operating models:

There is no single right operating model for AML/CTF compliance. The appropriate model depends on the size and complexity of the business, its risk profile, and the resources available. Common models include a fully in-house operations, compliance and risk function, a hybrid model that combines internal staff with external specialist support, and an outsourced model where some or all operations, compliance and risk functions are performed by a third party. Each has advantages and limitations.

  • In-house model - the operations, compliance and risk function is staffed entirely internally. This provides deep institutional knowledge and close integration with the business, but requires sufficient headcount and capability to cover all Program requirements, including during absences and transitions. An in-house model can itself be structured in two ways: centralised or federated
  • Centralised - a single compliance and risk function sits at the group or entity level and is responsible for the AML/CTF Program across the whole business. This model provides consistency, clear accountability, and economies of scale, but can become a bottleneck in larger or more complex organisations where business units have distinct risk profiles or operational needs
  • Federated - compliance and risk responsibilities are distributed across business units or divisions, with each unit maintaining its own compliance capability and the central function providing oversight, standards, and coordination. This model can be more responsive to the specific needs of each business unit, but requires strong governance to ensure consistency across the Program, reporting remains consistent and robust, and to avoid gaps or duplication at the boundaries between units
  • Hybrid model - internal staff manage day-to-day operations, compliance and risk functions, with external specialists engaged for specific tasks such as EWRA development, controls testing, independent review, or regulatory engagement. This is a common and practical model for mid-sized businesses
  • Outsourced model - some or all operations, compliance and risk functions are performed by an external provider. This can be appropriate for smaller businesses or those with limited internal capability, but the reporting entity remains legally responsible for the Program - outsourcing a function does not outsource the obligation
  • Regardless of the model, the AMLCO must be a real person within the organisation with genuine authority and accountability - the role cannot be fully outsourced

Consider the following actions (as they might apply to your operations):

  • Reviewing the resourcing of your compliance and risk function at least annually, and whenever there is a material change to the business or its risk profile
  • Documenting your operating model - including the split between internal and external resources - in your AML/CTF policies so that it is clear who is responsible for what. Capture this in job descriptions
  • Ensuring the board is informed of any material resourcing constraints that affect the Program's ability to operate effectively - this is a governance matter and should be on the board's radar
  • Conducting vendor due diligence on any third-party technology or service providers that perform AML/CTF functions, and ensuring contractual arrangements are in place that clearly allocate responsibility
  • Reviewing your technology stack periodically to ensure it remains fit for purpose - technology that was adequate when first implemented may not keep pace with changes to the business or the regulatory environment

Need support with your AML/CTF Program?

Lane Consulting & Advisory provides practical, hands-on support across all aspects of AML/CTF compliance - from risk appetite setting and risk assessments through to controls testing and independent review.