AML Compliance Guide

What's my first priority?

AML/CTF compliance tasks aren't all equally urgent or independent — some have hard regulatory deadlines, and others can't start until an earlier step is finished. Here's the practical order most Tranche 2 businesses should follow.

Last updated 13 July 2026

Sound familiar?

  • The obligations list reads like a dozen equally urgent things at once.
  • You don't know which tasks depend on others being finished first.
  • You're worried about spending a week on the wrong thing while a hard deadline passes.

The practical sequence

  • 1. Enrol with AUSTRAC — hard deadline, ~20 minutes, and a prerequisite for almost everything else administratively.
  • 2. Appoint and notify your compliance officer — also has a notification deadline, and the program in step 4 needs to name this person.
  • 3. Complete your ML/TF risk assessment — this has to come before the program, because the program is your response to the risks you've identified.
  • 4. Write your AML/CTF program — built directly on the risk assessment.
  • 5. Set up customer due diligence steps — operationalise the program for new (and where needed, existing) clients.
  • 6. Train staff and set up record-keeping/reporting habits — the ongoing, business-as-usual layer that keeps everything else honest.

Why this order matters

Writing a program before finishing a risk assessment means writing it twice — the program should describe how you manage the specific risks you found, not a generic template. Similarly, appointing a compliance officer after writing the program means going back to name them in a document that assumed a placeholder.

Deadlines to anchor your plan around

Enrolment and compliance officer notification: 29 July 2026. Core obligations (risk assessment, program, CDD, training): commence 1 July 2026. Full current dates are on the key dates page.

Coming soon

Priority Roadmap Generator

This interactive tool isn't built yet (planned component: PriorityRoadmapGenerator). Check back soon, or read the guidance above in the meantime.

Where this leaves you

An ordered, dependency-aware action plan instead of an undifferentiated checklist — so effort goes to the right thing at the right time.

Ready to tackle the risk assessment and program? See how the whole process normally works →

What does good AML/CTF compliance look like? →

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

This is general information, not legal advice. Always verify current requirements on the AUSTRAC website or seek professional advice for your specific situation.