AML Compliance Guide

How to create an AML/CTF program

A step-by-step walkthrough for building an AUSTRAC-compliant AML/CTF program under Tranche 2 — from your risk assessment through to independent evaluation.

Note: This is a summary of AUSTRAC guidance — not legal advice. Always read the source material and seek professional advice for your specific situation.

Last updated: 3 July 2026 · Written against AUSTRAC's published Tranche 2 guidance and the AML/CTF Act 2006 (Cth)

Short answer: to create an AML/CTF program under AUSTRAC Tranche 2, you (1) confirm which designated services you provide, (2) complete an ML/TF risk assessment, (3) appoint and register a compliance officer, (4) write policies covering governance, ongoing CDD, third-party reliance, and personnel due diligence and training — organised however suits your business, since AUSTRAC's old Part A / Part B structure was abolished on 31 March 2026, (5) get governance sign-off, (6) train relevant staff, and (7) schedule an independent evaluation at least once every 3 years. Most small Tranche 2 businesses can produce a working draft in a few hours using a structured tool or AUSTRAC's free sector Starter Kit, without a consultant.

The 8 steps

1

Confirm you're a reporting entity

~30 minutes

Check which of your services are a "designated service" listed in Schedule 1 of the AML/CTF Act — not your industry as a whole. A law firm might trigger obligations only when it manages client money in a transaction; a real estate agency only when it facilitates a sale or purchase.

Common mistake: Assuming every service your business offers is in scope, and building a program far bigger than you actually need — or the reverse, assuming you're exempt because you're small.
Check designated services by sector →
2

Complete your ML/TF risk assessment

1–3 hours

Identify and assess your money laundering, terrorism financing and proliferation financing (ML/TF) risk across your customer types, services, delivery channels (face-to-face vs remote) and geography — proliferation financing is an explicit requirement under AUSTRAC's reformed program guidance. This is Step 2 of AUSTRAC's program-development process, and the foundation everything else responds to: your policies exist to control the risks this step identifies.

Common mistake: Writing a generic risk statement instead of actually rating your specific customer base and services. AUSTRAC expects this to be a live document that's reviewed and updated, not a one-off box-tick.
3

Appoint your AML/CTF compliance officer

~1 day to decide + ongoing

Your compliance officer must be at management level, ordinarily resident in Australia, and a fit and proper person — they don't need to be a dedicated hire. The standing rule is to appoint one within 28 days of providing a designated service and notify AUSTRAC within 14 days of the appointment. If you're newly regulated under Tranche 2, the AML/CTF Transitional Rules 2026 instead give you until 29 July 2026 to notify AUSTRAC of your compliance officer.

Common mistake: Naming someone on paper who doesn't have real authority over the program, or leaving the role informally vacant while "figuring it out."
Compliance officer eligibility requirements →
4

Structure your program — there's no fixed template anymore

~30 minutes

AUSTRAC abolished the old prescriptive two-part "Part A / Part B" program structure on 31 March 2026. You no longer have to split your program into a risk-based Part A and a customer-identification Part B — you can organise it however works for your business, as a single consolidated document or several, provided it addresses governance, your risk assessment, ongoing CDD, third-party reliance, personnel due diligence and training, and independent evaluation, and is approved by senior management.

Common mistake: Following an old template, guide, or consultant brief that still describes a mandatory Part A / Part B split — that requirement no longer exists for any reporting entity, new or existing.
See the current requirements in full →
5

Write policies covering AUSTRAC's core requirements

Several hours to a couple of days

This is the largest single step. AUSTRAC requires every program to address governance, the ML/TF risk assessment, ongoing customer due diligence, third-party reliance (if any), and personnel due diligence and training, with a periodic independent evaluation on top. If you're a lawyer, accountant, or real estate agent newly regulated under Tranche 2, AUSTRAC's sector-specific Program Starter Kits are built around exactly these requirements and are a faster starting point than a generic template.

Common mistake: Copying a generic template's wording instead of describing what your business will actually do — a program that doesn't match your real process is a liability, not a shield, if AUSTRAC ever reviews it.
View the current requirements in detail →
6

Assemble your program document(s)

Rolls up the work above

AUSTRAC no longer mandates a specific document structure, but most businesses still find it practical to separate a risk assessment, a policy document (your governance structure and high-level commitments), and a process document (the operational procedures staff actually follow for CDD, reporting, training and escalation) — or to combine these into one consolidated program if that suits your size.

Common mistake: Merging everything into one document that's too high-level for staff to follow day-to-day, or too operational for a governing body to meaningfully approve.
7

Get governance sign-off, then train your staff

Varies by business size

Your program isn't valid until approved by senior management or your governing body — and that body needs to receive reports on program performance and risk from your compliance officer at least once every 12 months. Once approved, deliver AML/CTF risk-awareness training tailored to each role, and record who's completed it and when retraining is due.

Common mistake: Treating training as a one-off induction session rather than an ongoing, role-tailored, re-triggered activity.
Track training with the completion register →
8

Schedule your independent evaluation

Recurring — at least every 3 years

Your policies must require a periodic independent evaluation of the program, conducted by someone who wasn't responsible for the function being evaluated. AUSTRAC sets a maximum interval of 3 years, but a higher-risk or larger business may need to review more often. The AML/CTF Transitional Rules 2026 stagger the deadline for your first evaluation after the reforms, so check the current transitional timeline rather than assuming the 3-year clock starts today.

Common mistake: Writing "independent evaluation" into the policy document but never actually booking one, or having the compliance officer review their own work.

DIY vs template vs software vs consultant

Which route makes sense depends mostly on your size and risk, not your industry:

DIY from AUSTRAC guidance alone

Best for
A very simple sole practitioner with one or two designated services and low customer risk
Cost
Free — but expect a full weekend of reading and drafting
Watch out for
Easy to miss a required element buried across multiple AUSTRAC pages, and no built-in check that you've covered every core requirement

AUSTRAC's Program Starter Kit

Best for
Newly regulated Tranche 2 lawyers, accountants and real estate agents wanting an official starting template
Cost
Free, sector-specific document library
Watch out for
Still a template — you must customise it to your actual customers, services and risk profile before it's a valid program

Free program builder tool

Free
Best for
Most Tranche 2 small-to-mid practices wanting a structured, guided starting draft
Cost
Free, no account required to start
Watch out for
Produces a single consolidated draft (no Part A/Part B split) — you still need to review and tailor it to your actual business

Paid compliance software

Best for
Businesses that also want built-in identity verification, KYB, or higher transaction volumes
Cost
From roughly $59/month to $350+/month
Watch out for
Pricing models vary a lot — flat monthly fee vs charged per identity/screening check

Consultant or lawyer

Best for
Higher-risk, complex, or larger businesses — multiple entities, high-risk customer types, or prior AUSTRAC contact
Cost
Typically several thousand dollars upward
Watch out for
They can draft the document, but your compliance officer still owns the outcome — a bought program that doesn't match your real process is still your liability

See the full AML/CTF compliance platform comparison for named vendors and published pricing, or the AML compliance software buyer's guide if you're not yet sure you need software at all.

From document to daily practice

Writing the program is the start, not the finish. AUSTRAC expects the policy to be followed in practice, which means:

  • Ongoing customer due diligence — reviewing customers and dealings against their known risk profile, not just at onboarding
  • Documenting suspicious matter reporting decisions — including cases where you considered reporting and decided not to
  • Keeping records — AML/CTF records generally need to be retained for 7 years
  • Reviewing and updating the risk assessment and program as your business, customers or AUSTRAC guidance change

Frequently asked questions

How long does it take to create an AML/CTF program?

For a straightforward, low-risk Tranche 2 business — a sole practitioner or small firm with one or two designated services — a working first draft typically takes a few hours to a couple of days using a structured tool or template. More complex businesses with multiple entities, higher-risk customers, or several designated services should expect longer, and may benefit from professional input.

Do I need a lawyer to create an AML/CTF program?

Not necessarily. AUSTRAC's guidance is written for reporting entities to apply themselves, and a proportionate program for a small, low-risk business can reasonably be built using AUSTRAC's own materials or a purpose-built free tool. Larger, higher-risk, or previously non-compliant businesses are more likely to benefit from a lawyer or specialist consultant.

Can I use a template for my AML/CTF program?

Yes, provided it's tailored to your actual business — your real customers, services, delivery channels and risk profile. A generic or overseas (US/UK-style) template that hasn't been adapted to AUSTRAC's specific requirements and your business is a common source of gaps found during an independent evaluation.

Do I still need separate Part A and Part B documents?

No. AUSTRAC removed the prescriptive two-part Part A / Part B program structure on 31 March 2026. Reporting entities — new and existing — now build a single, risk-based AML/CTF program organised however suits the business, as long as it covers governance, the risk assessment, ongoing CDD, third-party reliance, personnel due diligence and training, and independent evaluation.

What is an AUSTRAC Program Starter Kit?

A free, sector-specific document library AUSTRAC publishes for newly regulated Tranche 2 businesses, currently covering the legal, accounting and real estate professions. It gives you an official starting template mapped to your sector's typical designated services, which you still need to customise to your actual business before it's a valid program.

What happens if AUSTRAC finds my program inadequate?

AUSTRAC has a range of regulatory responses available, from guidance and formal warnings through to enforcement action, generally proportionate to the nature and severity of the deficiency. This is general information, not legal advice — if you have specific concerns about an existing program, seek professional advice.

Do I need a separate program for each designated service I provide?

No — one AML/CTF program can cover multiple designated services, provided it addresses the risks and requirements relevant to each. Your risk assessment and policies should reflect the full range of services you actually provide.

Who has to approve the AML/CTF program?

Senior management or your governing body must approve the program and the risk assessment, along with any updates to either. For a small business this might be the owner or partners; for a larger business, a board or executive committee.

Can one person be both the compliance officer and write the program?

Yes — for a small business, it's common for the compliance officer to also draft the program. The independent evaluation requirement is what provides the separate check: that review must be carried out by someone other than the person responsible for the function being evaluated, at least once every 3 years.

What is the final step in creating an AML/CTF program?

AUSTRAC's own guidance frames program development as 5 steps: (1) establish your governance framework, including appointing a compliance officer, (2) identify and assess your risks, (3) manage and mitigate risks through AML/CTF policies, (4) review and update the program, and (5) conduct an independent evaluation — the final step. This page breaks that same process into 8 more granular steps, but Step 5 in AUSTRAC's numbering and the independent evaluation covered in Step 8 above are the same requirement.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Want the full requirements checklist?

See every requirement across all 6 minimum components in detail.

View requirements →

Comparing compliance platforms?

What to look for in an AML/CTF compliance platform, and how the options compare on cost and effort.

Read the buyer's guide →

References

  1. 1. Your AML/CTF program overview — AUSTRAC
  2. 2. Step 1: Establish your governance framework — AML/CTF compliance officer — AUSTRAC
  3. 3. Step 2: Identify and assess your risks — AUSTRAC
  4. 4. Step 3: Manage and mitigate your risks — AML/CTF policies — AUSTRAC
  5. 5. Step 4: Review and update your AML/CTF program — AUSTRAC
  6. 6. Step 5: Conduct an independent evaluation — AUSTRAC
  7. 7. Record keeping overview — AUSTRAC
  8. 8. Program starter kits — AUSTRAC
  9. 9. AML/CTF transitional rules 2026 — AUSTRAC

Not legal advice. AUSTRAC's guidance is updated as the 2026 AML/CTF reforms continue to roll out — verify current requirements on the AUSTRAC website before relying on this page.