AML Compliance Guide

AML/CTF program minimum requirements

Every reporting entity must develop, maintain, and comply with an AML/CTF program before providing a designated service. Since the AML/CTF reforms commenced on 31 March 2026, there's no mandated Part A / Part B document split — you organise your program however suits your business, provided it covers the components below. This page covers those minimum components — for the step-by-step process of actually building one, see how to create an AML/CTF program.

Note: This is a summary of AUSTRAC guidance — not legal advice. Always read the source material and seek professional advice for your specific situation.

What does a program actually look like?

AUSTRAC's starter kit material says a program typically consists of three documents:

Risk assessment

A documented assessment of the ML/TF risks specific to your customers, services, delivery channels, and geography.

Policy document

A high-level document setting out your commitment to AML/CTF compliance, governance structure, and key obligations.

Process document

Detailed procedures staff follow for CDD, reporting, training, and escalation — the operational layer of your program.

The 6 minimum components

1

Governance framework

Your program must document how AML/CTF governance operates across your business.

  • Outline governance roles, AML/CTF responsibilities and accountabilities
  • Outline eligibility requirements for the AML/CTF compliance officer
  • Outline how senior management or the governing body are informed of program performance and risks
  • Outline the process for the governing body to receive reports from the AML/CTF compliance officer at least once every 12 months
  • Outline the process for notifying AUSTRAC within 14 days of appointing an AML/CTF compliance officer
  • Document approval of policies and the risk assessment, and updates to these
2

ML/TF risk assessment

The program must document your money laundering and terrorism financing risk assessment and how it stays current.

  • Outline your business's ML/TF risk assessment
  • Document approval of the risk assessment
  • Outline how you will incorporate AUSTRAC guidance and risk updates
  • Outline the frequency and triggers for review
3

Ongoing customer due diligence

Your program must describe how you will monitor customers and dealings on an ongoing basis — not just at initial onboarding. This covers detecting when customer risk changes, keeping CDD information current, and applying enhanced measures when risk is elevated.

  • Define the triggers that will prompt a review of a customer's risk rating (e.g., instructions inconsistent with their known profile, unusual transaction patterns, adverse media, change in customer circumstances or purpose, negative name-screening results)
  • Describe how you will monitor ongoing dealings with customers for consistency with their known risk profile and expected behaviour
  • Outline how and when customer information will be refreshed or re-verified — at defined intervals, or when a risk trigger fires
  • Outline the enhanced due diligence (ECDD) measures you will apply to high-risk customers, such as obtaining more information, requiring senior or partner approval, or conducting more frequent reviews
  • Describe how OCDD findings will be escalated, documented, and how they feed into your suspicious matter reporting (SMR) process
Note: For Tranche 2 entities such as accountants and lawyers, 'transaction monitoring' does not require automated software. A proportionate manual process — for example, reviewing client instructions at each engagement against their known profile — is sufficient, provided it is consistently applied and documented.
4

Third-party reliance

If you rely on a third party for any part of your CDD obligations, the program must address this arrangement.

  • Outline any third-party services or reliance arrangements used for customer due diligence
  • Outline how you will ensure the third party has appropriate measures in place to comply with your AML/CTF obligations and implement them in practice
5

Personnel due diligence and training

This is the most detailed component — your program must address the suitability, vetting, and ongoing training of your people.

  • Specify which roles perform AML/CTF functions and require due diligence and training
  • Specify high-risk roles requiring tailored due diligence and training
  • Outline how you will ensure personnel have the skills, knowledge and expertise for AML/CTF functions
  • Outline how you will assess integrity, including background checks where appropriate
  • Outline the frequency and triggers for reassessment of personnel suitability
  • Outline how you will respond to adverse assessments
  • Provide AML/CTF risk awareness training to all relevant personnel
  • Outline training content and schedule tailored to roles and risks
  • Outline how training will be reviewed and updated over time
  • Outline retraining frequency and triggers
  • Record training completion dates and when further training is due
  • Monitor training effectiveness and whether personnel are applying it in practice
  • Document personnel suitability assessments and decisions to demonstrate compliance
6

Independent evaluation

Your program must require periodic independent review — not conducted by the compliance function itself.

  • Your AML/CTF policies must ensure independent evaluations are conducted
  • Policies must set out the frequency of independent evaluations
  • Frequency must be appropriate to the nature, size and complexity of the business
  • At a minimum, an independent evaluation must be conducted at least once every 3 years
Note: An independent evaluation cannot be performed by the same person responsible for the function being evaluated. For smaller businesses, this may mean engaging an external reviewer.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Not sure where to start?

A step-by-step walkthrough for actually building your program, from risk assessment to independent evaluation.

How to create an AML/CTF program →

AUSTRAC guidance summaries

Plain-English summaries of AUSTRAC's program and risk assessment guidance documents.

View guidance →

Comparing compliance platforms?

What to look for in an AML/CTF compliance platform, and how the options compare on cost and effort.

Read the buyer's guide →

Based on AUSTRAC's AML/CTF program guidance and sector Program Starter Kit material, current as of the AML/CTF reforms that commenced 31 March 2026. Not legal advice. Requirements may be updated as AUSTRAC publishes further guidance — verify on the AUSTRAC website.