AML Compliance Guide

What does good AML/CTF compliance look like?

AML/CTF compliance isn't a single document or a one-off project — it's a cycle: assess risk, document a program, apply it to real clients, monitor, and periodically review. Here's how that cycle plays out in practice for a typical Tranche 2 business.

Last updated 13 July 2026

Sound familiar?

  • You understand the individual obligations but not how they fit together as a process.
  • You don't know what a finished AML/CTF program actually looks like as a document.
  • You're not sure whether compliance is a one-off project or an ongoing routine.

The implementation lifecycle

  • Risk assessment — a written analysis of your specific ML/TF exposure across clients, services, delivery channels, and geography.
  • AML/CTF program — governance, risk assessment reference, ongoing CDD approach, personnel due diligence and training, and independent evaluation arrangements, usually split across a policy document and a process document.
  • Day-to-day application — verifying new client identity and beneficial ownership before providing a designated service, and applying enhanced checks to higher-risk clients.
  • Ongoing monitoring — watching for changes in client behaviour or risk that don't match what you know about them, and escalating anything suspicious.
  • Independent evaluation — a periodic review (at least every 3 years) by someone other than the person who runs the program day to day.

What does a finished program look like?

AUSTRAC's starter kit material describes a program typically split into three documents: a risk assessment, a policy document (your high-level commitments and governance), and a process document (the operational steps staff actually follow). Most small firms adapt AUSTRAC's free templates rather than writing from a blank page.

Where this leaves you

Understanding of the implementation sequence and what 'done' looks like in practice, ready to start gathering your own specific requirements.

Ready to build yours? See exactly which documents and registers you need →

What documents are mandatory? →

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

This is general information, not legal advice. Always verify current requirements on the AUSTRAC website or seek professional advice for your specific situation.