AML Compliance Guide

How compliant am I today?

Most businesses starting Tranche 2 compliance aren't starting from zero — you likely already verify client ID for other reasons, keep records, and have some internal processes. A gap assessment measures what you already do against AUSTRAC's six core obligations, so you know exactly what's missing rather than rebuilding everything from scratch.

Last updated 13 July 2026

Sound familiar?

  • You don't know if the basic policies you already have (privacy, ID checks for other reasons) count for anything.
  • You have no idea how much work is left versus how much is already done.
  • Everything you read describes the end state, not where you're starting from.

Score yourself against the six core obligations

  • Enrolment — have you registered your business in AUSTRAC Online?
  • Compliance officer — has someone been formally nominated and notified to AUSTRAC?
  • Risk assessment — is there a written document assessing your specific ML/TF risks, or does it only exist in your head?
  • AML/CTF program — do you have a written policy, or only informal habits?
  • Customer due diligence — do you verify identity and beneficial ownership consistently, or only sometimes?
  • Record keeping and reporting — can you retrieve 7 years of records, and would staff know how to escalate a suspicious matter?

Common starting points

Firms that already handle client money (trust accounts) or already do ID checks for conveyancing, property settlement, or KYC under another regime (like real estate underquoting rules) tend to be closer to compliant than they think — the gap is usually in documentation and consistency, not in inventing new processes from nothing.

Coming soon

Compliance Gap Assessment

This interactive tool isn't built yet (planned component: ComplianceGapAssessment). Check back soon, or read the guidance above in the meantime.

Where this leaves you

A realistic picture of what you already have covered, what's missing, and roughly how big the remaining gap is — so you can plan work instead of guessing at it.

Know your gaps? Work out what to tackle first →

What's my first priority? →

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Does having a privacy policy count toward my AML/CTF program?
Not directly — a privacy policy covers different obligations (the Privacy Act). It may reuse some of the same client data-handling processes, but AUSTRAC requires a specific AML/CTF program covering the six minimum components.
What's a realistic gap for a small firm with no prior compliance program?
Most small firms starting from nothing need to build a risk assessment and program from a template (a few hours' work), formalise ID verification steps they may already do informally, and set up a record-keeping and reporting process. It's rarely a multi-month project for a straightforward business.
Should I do a gap assessment before or after enrolling with AUSTRAC?
Either order works, but many businesses enrol first (it's quick, roughly 20 minutes) and use the gap assessment to plan the risk assessment and program work that follows.

This is general information, not legal advice. Always verify current requirements on the AUSTRAC website or seek professional advice for your specific situation.