Back to Articles

AML

Independent Evaluation of Your AML/CTF Program Under the 2025 Reforms

July 2026 · Lane Consulting & Advisory

Australia's AML/CTF Act and Rules 2025 have replaced the obligation to conduct an Independent Review with a new obligation to conduct an Independent Evaluation. The terminology has changed, the framework has been updated, and the scope has broadened - but the underlying purpose remains the same: to give your Board and senior management independent assurance that your AML/CTF Program is adequate and effective.

If you are familiar with the Independent Review obligation under the old framework, much of what follows will be recognisable. But there are meaningful differences, and this article sets out both.

What Has Stayed the Same

The core purpose of the obligation has not changed. An Independent Evaluation, like an Independent Review before it, is an impartial assessment of your AML/CTF Program conducted by someone who is independent of its development and operation. It is designed to answer the same fundamental questions:

  • Is your Program adequate to identify and manage your ML/TF/PF risks?
  • Is your Program actually working in practice?
  • Are you meeting your legal obligations under the AML/CTF Act and Rules?

The independence requirement is also unchanged in substance. The person conducting the evaluation must be independent of the build and operation of your Program. They must not be marking their own homework. Whether you use an internal resource or an external consultant, the same principles apply: no involvement in developing the Program, appropriate expertise, and the ability to bring genuine objectivity to the assessment.

The four-step methodology that characterises a well-conducted review - documentation review, interviews, sample testing, and site visits - remains the appropriate approach for an Independent Evaluation. Your evaluator should still be examining your Program documentation, speaking with key personnel, testing controls against records, and (where relevant) visiting the locations where your Program is implemented.

The output is also the same: a written report setting out findings and recommendations, which must be provided to your Board and senior management. That report should still show what was tested, how it was tested, the sample sizes used, any limitations of the evaluation, and the evaluator's conclusions.

And the obligation to act on findings has not changed. Deficiencies identified in an Independent Evaluation must be remediated. Your Board and senior management must be kept informed of progress. The evaluation feeds into your next risk assessment cycle.

What Has Changed

The name - and what it signals

The shift from 'Independent Review' to 'Independent Evaluation' is not merely cosmetic. The word 'evaluation' carries a stronger connotation of assessed effectiveness - not just whether your Program exists and is documented, but whether it is actually working. This aligns with AUSTRAC's broader regulatory posture under the 2025 reforms, which places greater emphasis on outcomes and effectiveness rather than procedural compliance.

Scope: the whole Program, not just Part A

Under the old framework, the Independent Review obligation applied to Part A of your AML/CTF Program - the risk-based part. Part B (customer due diligence) was technically outside the mandatory scope, though good practice was to include it.

Under the AML/CTF Rules 2025, the Independent Evaluation applies to your AML/CTF Program as a whole. The distinction between Part A and Part B no longer exists in the same form - the 2025 reforms have restructured the Program obligations - and the evaluation obligation reflects that broader scope. Your evaluator should be assessing your entire compliance framework, including your customer due diligence and ongoing due diligence arrangements.

Frequency: a three-year maximum, applied consistently

Under the old framework, the frequency of Independent Reviews was risk-based, with higher-risk entities expected to review more frequently (annually, in some cases) and lower-risk entities able to extend the cycle to two or three years. The three-year maximum was introduced as a floor, not a ceiling.

Under the AML/CTF Rules 2025, the maximum interval between Independent Evaluations is three years. The risk-based principle still applies - higher-risk entities should evaluate more frequently - but the three-year outer limit is now clearly established in the Rules. If your last review was conducted under the old framework, you should assess when your next evaluation is due under the new timetable.

Proliferation financing is now in scope

The 2025 reforms formally introduced proliferation financing (PF) risk as a compliance obligation for reporting entities. Your AML/CTF Program must now address ML/TF/PF risks - not just ML/TF. The Independent Evaluation must therefore assess whether your Program adequately identifies and manages your PF risks, in addition to your ML and TF risks.

For many, but not all, entities, PF risk will be low. But it must be assessed, documented, and addressed in your Program - and your evaluator should be looking at whether that has been done.

Greater emphasis on governance and culture

The 2025 reforms place greater weight on governance, accountability, and compliance culture as indicators of Program effectiveness. An Independent Evaluation conducted under the new framework should go beyond testing whether controls exist and are documented - it should assess whether your governance arrangements are genuinely supporting compliance, whether your Board and senior management are receiving meaningful information, and whether your compliance culture is consistent with your stated obligations.

This is not entirely new - a well-conducted Independent Review always looked at governance - but the 2025 framework makes it a more explicit part of the evaluation scope.

At a Glance: Independent Review vs Independent Evaluation

FeatureIndependent Review (old)Independent Evaluation (2025)
PurposeAssess adequacy and effectiveness of Part AAssess adequacy and effectiveness of the whole Program
ScopePart A (risk-based program); Part B optionalEntire AML/CTF Program, including CDD/ODD
PF riskNot formally in scopeIn scope - ML/TF/PF risks must be assessed
FrequencyRisk-based; 3 years as outer limit (introduced late in old framework)Risk-based; 3 years maximum, clearly established in Rules
Independence requirementIndependent of Program build and operationUnchanged - independent of Program build and operation
MethodologyDocumentation, interviews, sample testing, site visitsUnchanged - same four-step approach remains appropriate
OutputWritten report to Board / senior managementUnchanged - written report to Board / senior management
Governance focusIncluded in scope, but not always emphasisedMore explicitly in scope under 2025 framework
Remediation obligationFindings must be addressedUnchanged - findings must be addressed

What Should You Do Now?

If your last Independent Review was conducted under the old framework, you should:

  • confirm when your next Independent Evaluation is due under the three-year maximum in the AML/CTF Rules 2025;
  • review the scope of your last review against the broader scope of the Independent Evaluation obligation - particularly whether Part B / CDD arrangements and PF risks were adequately covered;
  • ensure your evaluator understands the 2025 framework and is assessing your Program against the new obligations, not the old ones; and
  • consider whether your Program documentation has been updated to reflect the 2025 reforms before the evaluation commences - an evaluator assessing a Program that has not been updated will find gaps that are structural, not operational.

The Independent Evaluation is not just a compliance checkbox. It is the mechanism by which your Board and senior management receive independent assurance that your approach to compliance is working. Used well, it is one of the most valuable tools in your AML/CTF governance framework.