AML Compliance Guide

Staff training for Trust and company service providerss — 2026 AUSTRAC Guide

If your business provides trust and company services that are designated services from 1 July 2026, you must train the people who onboard clients, set up companies or trusts, handle client instructions, move funds, or review ownership and control. This applies because your staff are often the first to spot nominee arrangements, complex ownership chains, unexplained source of funds issues, sanctions risks, and suspicious attempts to hide a beneficial owner. If you do not train staff properly, you risk breaches across customer due diligence, sanctions screening, suspicious matter reporting and record keeping, with civil penalties up to $33.5 million per contravention and criminal penalties for intentional contraventions.

Staff training is not a one-off induction module. Your AML/CTF program must include documented training for all staff who deal with customers or handle relevant transactions, and the training must match what they actually do in your practice. For a trust and company service provider, that usually means different training for front-desk staff, onboarding staff, directors, relationship managers, trust administration staff, and anyone reviewing complex structures, foreign ownership, source of funds or politically exposed persons. AUSTRAC expects training to be understandable, role-based and updated when your business, risks or AML/CTF program changes.

What you need to do

  • Map your roles first: identify who forms entities, appoints directors or trustees, provides registered office or nominee services, handles client money, verifies beneficial owners, conducts sanctions screening, or escalates suspicious activity.
  • Build training into your AML/CTF program and finalise that program by 31 December 2026. Your training content should reflect your ML/TF risk assessment, including customer types, service risks, delivery channels, geography and proliferation financing risk.
  • Train each group on the tasks they perform: how to verify individuals, companies and trusts; how to identify a beneficial owner at the 25%+ threshold or effective control; when enhanced due diligence is required; how to screen against DFAT and UN sanctions lists; and when to escalate a suspicious matter.
  • Keep records of who was trained, when, what content they received and how you tested understanding. Repeat training when the program is updated or when legal changes, new risks, review findings or breaches show a gap.

Training frequency AUSTRAC expects

AML/CTF compliance officers and senior management: every 6–12 months. Customer-facing personnel: every 12 months. Personnel responsible for onboarding, transaction monitoring or other enhanced CDD roles: every 12 months. Third-party vendors: when onboarded, and when the contract is renewed or changed. All other personnel not in AML/CTF-relevant roles: general awareness training at onboarding.

The biggest mistake for this profession is relying on generic AML slides that never mention trusts, shelf companies, nominee shareholders, corporate trustees, layered offshore ownership or source of wealth for settlors and controllers. Another common error is training only compliance staff and not the people who actually receive client instructions or collect documents. E-learning can help, but AUSTRAC says it cannot be your only solution unless you tailor it to the person’s AML/CTF function, the risks relevant to that function and their responsibilities under your policies. If you outsource training, you still remain responsible for making sure it fits your services and your risk profile.

Practical training topics for trust and company service providers

  • How to identify the real controller where a structure uses multiple companies, trusts, protectors, appointors or nominee arrangements.
  • Red flags when a client wants a company or trust set up quickly with vague commercial reasons, unusual urgency, inconsistent identity documents, or reluctance to disclose beneficial owners.
  • How to handle foreign clients, high-risk jurisdictions, sanctions screening matches and proliferation financing concerns, especially where structures connect to dual-use goods, defence-related trade or opaque overseas intermediaries.
  • What staff must never say if an SMR is being considered or filed, because tipping off the customer is a separate criminal offence.

A lightweight AML platform, built exclusively for Tranche 2

Get AUSTRAC's mandates done as fast and effortless as possible.

  • Built around AUSTRAC's actual requirements
  • Single maintained compliance file
  • No compliance expertise required
  • 25 minute initial compliance setup
  • Obligations calendar & reminders
  • Instant data export
Setup: ~25 minutes Ongoing: minutes per client Price: $8 per KYC
See the product →

Frequently asked questions

Do I need to train everyone in the business, or only the people doing onboarding?
You must train all staff who deal with customers or handle relevant transactions, and the training must match their role. In a trust and company service provider, that usually extends beyond onboarding to relationship managers, trust administration staff, directors, and anyone reviewing ownership, control, payments or unusual client instructions. Staff outside AML/CTF-relevant roles still need general awareness training at onboarding.
Can I just use AUSTRAC e-learning modules or an industry course?
No, not by themselves. AUSTRAC says its e-learning can be used as part of your training, but it cannot be relied on solely because your training must be tailored to the person’s role, the ML/TF risks relevant to that role and your own AML/CTF policies. Generic external training usually needs to be supplemented with examples from your trust, company formation and administration work.
What if I use an outsourced company secretarial team or external onboarding provider?
Third-party vendors should be trained when they are onboarded and when the contract is renewed or changed. You remain responsible for making sure their training is suitable, understandable and aligned with your AML/CTF program. You should also do due diligence on the provider and set clear expectations about sanctions screening, beneficial ownership checks, escalation and record keeping.
How much does AML/CTF training have to cost?
The law does not set a minimum spend or require expensive software. What matters is whether the training is effective, role-based, documented and matched to the risks in your business. A small practice can use a mix of induction sessions, short role-based modules, case studies from real files, supervisor coaching and periodic refreshers.
What is the best practical way to document that training actually happened?
Keep a training register that records the staff member’s name, role, date, delivery method, topics covered and any quiz, assessment or sign-off. Save copies of slides, case studies, attendance records, policy updates and vendor training records. If your AML/CTF program changes, record the retraining date and what changed so you can show AUSTRAC the training was kept current.