How to create an AML/CTF program
A step-by-step walkthrough for building an AUSTRAC-compliant AML/CTF program under Tranche 2 — from your risk assessment through to independent evaluation.
Note: This is a summary of AUSTRAC guidance — not legal advice. Always read the source material and seek professional advice for your specific situation.
Last updated: 3 July 2026 · Written against AUSTRAC's published Tranche 2 guidance and the AML/CTF Act 2006 (Cth)
Short answer: to create an AML/CTF program under AUSTRAC Tranche 2, you (1) confirm which designated services you provide, (2) complete an ML/TF risk assessment, (3) appoint and register a compliance officer, (4) write policies covering governance, ongoing CDD, third-party reliance, and personnel due diligence and training — organised however suits your business, since AUSTRAC's old Part A / Part B structure was abolished on 31 March 2026, (5) get governance sign-off, (6) train relevant staff, and (7) schedule an independent evaluation at least once every 3 years. Most small Tranche 2 businesses can produce a working draft in a few hours using a structured tool or AUSTRAC's free sector Starter Kit, without a consultant.
The 8 steps
Confirm you're a reporting entity
Check which of your services are a "designated service" listed in Schedule 1 of the AML/CTF Act — not your industry as a whole. A law firm might trigger obligations only when it manages client money in a transaction; a real estate agency only when it facilitates a sale or purchase.
Complete your ML/TF risk assessment
Identify and assess your money laundering, terrorism financing and proliferation financing (ML/TF) risk across your customer types, services, delivery channels (face-to-face vs remote) and geography — proliferation financing is an explicit requirement under AUSTRAC's reformed program guidance. This is Step 2 of AUSTRAC's program-development process, and the foundation everything else responds to: your policies exist to control the risks this step identifies.
Appoint your AML/CTF compliance officer
Your compliance officer must be at management level, ordinarily resident in Australia, and a fit and proper person — they don't need to be a dedicated hire. The standing rule is to appoint one within 28 days of providing a designated service and notify AUSTRAC within 14 days of the appointment. If you're newly regulated under Tranche 2, the AML/CTF Transitional Rules 2026 instead give you until 29 July 2026 to notify AUSTRAC of your compliance officer.
Structure your program — there's no fixed template anymore
AUSTRAC abolished the old prescriptive two-part "Part A / Part B" program structure on 31 March 2026. You no longer have to split your program into a risk-based Part A and a customer-identification Part B — you can organise it however works for your business, as a single consolidated document or several, provided it addresses governance, your risk assessment, ongoing CDD, third-party reliance, personnel due diligence and training, and independent evaluation, and is approved by senior management.
Write policies covering AUSTRAC's core requirements
This is the largest single step. AUSTRAC requires every program to address governance, the ML/TF risk assessment, ongoing customer due diligence, third-party reliance (if any), and personnel due diligence and training, with a periodic independent evaluation on top. If you're a lawyer, accountant, or real estate agent newly regulated under Tranche 2, AUSTRAC's sector-specific Program Starter Kits are built around exactly these requirements and are a faster starting point than a generic template.
Assemble your program document(s)
AUSTRAC no longer mandates a specific document structure, but most businesses still find it practical to separate a risk assessment, a policy document (your governance structure and high-level commitments), and a process document (the operational procedures staff actually follow for CDD, reporting, training and escalation) — or to combine these into one consolidated program if that suits your size.
Get governance sign-off, then train your staff
Your program isn't valid until approved by senior management or your governing body — and that body needs to receive reports on program performance and risk from your compliance officer at least once every 12 months. Once approved, deliver AML/CTF risk-awareness training tailored to each role, and record who's completed it and when retraining is due.
Schedule your independent evaluation
Your policies must require a periodic independent evaluation of the program, conducted by someone who wasn't responsible for the function being evaluated. AUSTRAC sets a maximum interval of 3 years, but a higher-risk or larger business may need to review more often. The AML/CTF Transitional Rules 2026 stagger the deadline for your first evaluation after the reforms, so check the current transitional timeline rather than assuming the 3-year clock starts today.
DIY vs template vs software vs consultant
Which route makes sense depends mostly on your size and risk, not your industry:
DIY from AUSTRAC guidance alone
- Best for
- A very simple sole practitioner with one or two designated services and low customer risk
- Cost
- Free — but expect a full weekend of reading and drafting
- Watch out for
- Easy to miss a required element buried across multiple AUSTRAC pages, and no built-in check that you've covered every core requirement
AUSTRAC's Program Starter Kit
- Best for
- Newly regulated Tranche 2 lawyers, accountants and real estate agents wanting an official starting template
- Cost
- Free, sector-specific document library
- Watch out for
- Still a template — you must customise it to your actual customers, services and risk profile before it's a valid program
Free program builder tool
Free- Best for
- Most Tranche 2 small-to-mid practices wanting a structured, guided starting draft
- Cost
- Free, no account required to start
- Watch out for
- Produces a single consolidated draft (no Part A/Part B split) — you still need to review and tailor it to your actual business
Paid compliance software
- Best for
- Businesses that also want built-in identity verification, KYB, or higher transaction volumes
- Cost
- From roughly $59/month to $350+/month
- Watch out for
- Pricing models vary a lot — flat monthly fee vs charged per identity/screening check
Consultant or lawyer
- Best for
- Higher-risk, complex, or larger businesses — multiple entities, high-risk customer types, or prior AUSTRAC contact
- Cost
- Typically several thousand dollars upward
- Watch out for
- They can draft the document, but your compliance officer still owns the outcome — a bought program that doesn't match your real process is still your liability
See the full AML/CTF compliance platform comparison for named vendors and published pricing, or the AML compliance software buyer's guide if you're not yet sure you need software at all.
From document to daily practice
Writing the program is the start, not the finish. AUSTRAC expects the policy to be followed in practice, which means:
- Ongoing customer due diligence — reviewing customers and dealings against their known risk profile, not just at onboarding
- Documenting suspicious matter reporting decisions — including cases where you considered reporting and decided not to
- Keeping records — AML/CTF records generally need to be retained for 7 years
- Reviewing and updating the risk assessment and program as your business, customers or AUSTRAC guidance change
Frequently asked questions
How long does it take to create an AML/CTF program?
For a straightforward, low-risk Tranche 2 business — a sole practitioner or small firm with one or two designated services — a working first draft typically takes a few hours to a couple of days using a structured tool or template. More complex businesses with multiple entities, higher-risk customers, or several designated services should expect longer, and may benefit from professional input.
Do I need a lawyer to create an AML/CTF program?
Not necessarily. AUSTRAC's guidance is written for reporting entities to apply themselves, and a proportionate program for a small, low-risk business can reasonably be built using AUSTRAC's own materials or a purpose-built free tool. Larger, higher-risk, or previously non-compliant businesses are more likely to benefit from a lawyer or specialist consultant.
Can I use a template for my AML/CTF program?
Yes, provided it's tailored to your actual business — your real customers, services, delivery channels and risk profile. A generic or overseas (US/UK-style) template that hasn't been adapted to AUSTRAC's specific requirements and your business is a common source of gaps found during an independent evaluation.
Do I still need separate Part A and Part B documents?
No. AUSTRAC removed the prescriptive two-part Part A / Part B program structure on 31 March 2026. Reporting entities — new and existing — now build a single, risk-based AML/CTF program organised however suits the business, as long as it covers governance, the risk assessment, ongoing CDD, third-party reliance, personnel due diligence and training, and independent evaluation.
What is an AUSTRAC Program Starter Kit?
A free, sector-specific document library AUSTRAC publishes for newly regulated Tranche 2 businesses, currently covering the legal, accounting and real estate professions. It gives you an official starting template mapped to your sector's typical designated services, which you still need to customise to your actual business before it's a valid program.
What happens if AUSTRAC finds my program inadequate?
AUSTRAC has a range of regulatory responses available, from guidance and formal warnings through to enforcement action, generally proportionate to the nature and severity of the deficiency. This is general information, not legal advice — if you have specific concerns about an existing program, seek professional advice.
Do I need a separate program for each designated service I provide?
No — one AML/CTF program can cover multiple designated services, provided it addresses the risks and requirements relevant to each. Your risk assessment and policies should reflect the full range of services you actually provide.
Who has to approve the AML/CTF program?
Senior management or your governing body must approve the program and the risk assessment, along with any updates to either. For a small business this might be the owner or partners; for a larger business, a board or executive committee.
Can one person be both the compliance officer and write the program?
Yes — for a small business, it's common for the compliance officer to also draft the program. The independent evaluation requirement is what provides the separate check: that review must be carried out by someone other than the person responsible for the function being evaluated, at least once every 3 years.
What is the final step in creating an AML/CTF program?
AUSTRAC's own guidance frames program development as 5 steps: (1) establish your governance framework, including appointing a compliance officer, (2) identify and assess your risks, (3) manage and mitigate risks through AML/CTF policies, (4) review and update the program, and (5) conduct an independent evaluation — the final step. This page breaks that same process into 8 more granular steps, but Step 5 in AUSTRAC's numbering and the independent evaluation covered in Step 8 above are the same requirement.
A lightweight AML platform, built exclusively for Tranche 2
Get AUSTRAC's mandates done as fast and effortless as possible.
- Built around AUSTRAC's actual requirements
- Single maintained compliance file
- No compliance expertise required
- 25 minute initial compliance setup
- Obligations calendar & reminders
- Instant data export
Want the full requirements checklist?
See every requirement across all 6 minimum components in detail.
View requirements →Comparing compliance platforms?
What to look for in an AML/CTF compliance platform, and how the options compare on cost and effort.
Read the buyer's guide →References
- 1. Your AML/CTF program overview — AUSTRAC
- 2. Step 1: Establish your governance framework — AML/CTF compliance officer — AUSTRAC
- 3. Step 2: Identify and assess your risks — AUSTRAC
- 4. Step 3: Manage and mitigate your risks — AML/CTF policies — AUSTRAC
- 5. Step 4: Review and update your AML/CTF program — AUSTRAC
- 6. Step 5: Conduct an independent evaluation — AUSTRAC
- 7. Record keeping overview — AUSTRAC
- 8. Program starter kits — AUSTRAC
- 9. AML/CTF transitional rules 2026 — AUSTRAC
Not legal advice. AUSTRAC's guidance is updated as the 2026 AML/CTF reforms continue to roll out — verify current requirements on the AUSTRAC website before relying on this page.