What's my first priority?
AML/CTF compliance tasks aren't all equally urgent or independent — some have hard regulatory deadlines, and others can't start until an earlier step is finished. Here's the practical order most Tranche 2 businesses should follow.
Last updated 13 July 2026
Sound familiar?
- The obligations list reads like a dozen equally urgent things at once.
- You don't know which tasks depend on others being finished first.
- You're worried about spending a week on the wrong thing while a hard deadline passes.
The practical sequence
- 1. Enrol with AUSTRAC — hard deadline, ~20 minutes, and a prerequisite for almost everything else administratively.
- 2. Appoint and notify your compliance officer — also has a notification deadline, and the program in step 4 needs to name this person.
- 3. Complete your ML/TF risk assessment — this has to come before the program, because the program is your response to the risks you've identified.
- 4. Write your AML/CTF program — built directly on the risk assessment.
- 5. Set up customer due diligence steps — operationalise the program for new (and where needed, existing) clients.
- 6. Train staff and set up record-keeping/reporting habits — the ongoing, business-as-usual layer that keeps everything else honest.
Why this order matters
Writing a program before finishing a risk assessment means writing it twice — the program should describe how you manage the specific risks you found, not a generic template. Similarly, appointing a compliance officer after writing the program means going back to name them in a document that assumed a placeholder.
Deadlines to anchor your plan around
Enrolment and compliance officer notification: 29 July 2026. Core obligations (risk assessment, program, CDD, training): commence 1 July 2026. Full current dates are on the key dates page.
Related reading
Coming soon
Priority Roadmap Generator
This interactive tool isn't built yet (planned component: PriorityRoadmapGenerator). Check back soon, or read the guidance above in the meantime.
Where this leaves you
An ordered, dependency-aware action plan instead of an undifferentiated checklist — so effort goes to the right thing at the right time.
Ready to tackle the risk assessment and program? See how the whole process normally works →
What does good AML/CTF compliance look like? →A lightweight AML platform, built exclusively for Tranche 2
Get AUSTRAC's mandates done as fast and effortless as possible.
- Built around AUSTRAC's actual requirements
- Single maintained compliance file
- No compliance expertise required
- 25 minute initial compliance setup
- Obligations calendar & reminders
- Instant data export
This is general information, not legal advice. Always verify current requirements on the AUSTRAC website or seek professional advice for your specific situation.