AML/CTF program minimum requirements
Every reporting entity must develop, maintain, and comply with an AML/CTF program before providing a designated service. Since the AML/CTF reforms commenced on 31 March 2026, there's no mandated Part A / Part B document split — you organise your program however suits your business, provided it covers the components below. This page covers those minimum components — for the step-by-step process of actually building one, see how to create an AML/CTF program.
Note: This is a summary of AUSTRAC guidance — not legal advice. Always read the source material and seek professional advice for your specific situation.
What does a program actually look like?
AUSTRAC's starter kit material says a program typically consists of three documents:
Risk assessment
A documented assessment of the ML/TF risks specific to your customers, services, delivery channels, and geography.
Policy document
A high-level document setting out your commitment to AML/CTF compliance, governance structure, and key obligations.
Process document
Detailed procedures staff follow for CDD, reporting, training, and escalation — the operational layer of your program.
The 6 minimum components
Governance framework
Your program must document how AML/CTF governance operates across your business.
- Outline governance roles, AML/CTF responsibilities and accountabilities
- Outline eligibility requirements for the AML/CTF compliance officer
- Outline how senior management or the governing body are informed of program performance and risks
- Outline the process for the governing body to receive reports from the AML/CTF compliance officer at least once every 12 months
- Outline the process for notifying AUSTRAC within 14 days of appointing an AML/CTF compliance officer
- Document approval of policies and the risk assessment, and updates to these
ML/TF risk assessment
The program must document your money laundering and terrorism financing risk assessment and how it stays current.
- Outline your business's ML/TF risk assessment
- Document approval of the risk assessment
- Outline how you will incorporate AUSTRAC guidance and risk updates
- Outline the frequency and triggers for review
Ongoing customer due diligence
Your program must describe how you will monitor customers and dealings on an ongoing basis — not just at initial onboarding. This covers detecting when customer risk changes, keeping CDD information current, and applying enhanced measures when risk is elevated.
- Define the triggers that will prompt a review of a customer's risk rating (e.g., instructions inconsistent with their known profile, unusual transaction patterns, adverse media, change in customer circumstances or purpose, negative name-screening results)
- Describe how you will monitor ongoing dealings with customers for consistency with their known risk profile and expected behaviour
- Outline how and when customer information will be refreshed or re-verified — at defined intervals, or when a risk trigger fires
- Outline the enhanced due diligence (ECDD) measures you will apply to high-risk customers, such as obtaining more information, requiring senior or partner approval, or conducting more frequent reviews
- Describe how OCDD findings will be escalated, documented, and how they feed into your suspicious matter reporting (SMR) process
Third-party reliance
If you rely on a third party for any part of your CDD obligations, the program must address this arrangement.
- Outline any third-party services or reliance arrangements used for customer due diligence
- Outline how you will ensure the third party has appropriate measures in place to comply with your AML/CTF obligations and implement them in practice
Personnel due diligence and training
This is the most detailed component — your program must address the suitability, vetting, and ongoing training of your people.
- Specify which roles perform AML/CTF functions and require due diligence and training
- Specify high-risk roles requiring tailored due diligence and training
- Outline how you will ensure personnel have the skills, knowledge and expertise for AML/CTF functions
- Outline how you will assess integrity, including background checks where appropriate
- Outline the frequency and triggers for reassessment of personnel suitability
- Outline how you will respond to adverse assessments
- Provide AML/CTF risk awareness training to all relevant personnel
- Outline training content and schedule tailored to roles and risks
- Outline how training will be reviewed and updated over time
- Outline retraining frequency and triggers
- Record training completion dates and when further training is due
- Monitor training effectiveness and whether personnel are applying it in practice
- Document personnel suitability assessments and decisions to demonstrate compliance
Independent evaluation
Your program must require periodic independent review — not conducted by the compliance function itself.
- Your AML/CTF policies must ensure independent evaluations are conducted
- Policies must set out the frequency of independent evaluations
- Frequency must be appropriate to the nature, size and complexity of the business
- At a minimum, an independent evaluation must be conducted at least once every 3 years
A lightweight AML platform, built exclusively for Tranche 2
Get AUSTRAC's mandates done as fast and effortless as possible.
- Built around AUSTRAC's actual requirements
- Single maintained compliance file
- No compliance expertise required
- 25 minute initial compliance setup
- Obligations calendar & reminders
- Instant data export
Not sure where to start?
A step-by-step walkthrough for actually building your program, from risk assessment to independent evaluation.
How to create an AML/CTF program →AUSTRAC guidance summaries
Plain-English summaries of AUSTRAC's program and risk assessment guidance documents.
View guidance →Comparing compliance platforms?
What to look for in an AML/CTF compliance platform, and how the options compare on cost and effort.
Read the buyer's guide →Based on AUSTRAC's AML/CTF program guidance and sector Program Starter Kit material, current as of the AML/CTF reforms that commenced 31 March 2026. Not legal advice. Requirements may be updated as AUSTRAC publishes further guidance — verify on the AUSTRAC website.