Australian AML/CTF Compliance Checklist
Use this free on-page checklist to see which core AML/CTF duties have been dealt with and what may still need work.
How this guide was researched and reviewedOn this page
Short answer
A reporting entity needs more than a written policy. Its scope, people, risk assessment, customer checks, reporting, records and review process must all work together.
This checklist covers the main duties for reporting entities. Extra duties can apply to a sector, service, reporting group or transaction.
At a glance
Start With These Four Questions
Is the scope written down?
Each designated service and its link to Australia should be recorded.
Is the program in use?
The risk assessment and AML/CTF policies should guide real work, not sit on a shelf.
Can the work be proved?
Records should show customer checks, decisions, reports, training and review.
Is it kept current?
Changes to services, customers, countries, systems and risk should be picked up.
Plain English
Key Words Explained
These words are used in the law and official guidance. This is what they mean on this page.
- AML/CTF
- Rules that help stop money laundering, terrorism financing and proliferation financing.
- Reporting entity
- A business or person that must follow AML/CTF rules for a service it provides.
- Designated service
- A service named in section 6 of the Australian AML/CTF Act.
- CDD
- Customer due diligence. These are checks used to know the customer and understand their risk.
- SMR
- Suspicious matter report. This is sent to AUSTRAC when the legal test for suspicion is met.
- Independent evaluation
- A check by a suitable independent person to see whether the AML/CTF program meets the rules and works.
Part 1
Work Through the Core Duties
Tick an item only when it has been completed and evidence can be shown. Your progress stays in this browser and is not saved.
Nothing has been marked complete yet.
Part 2
How to Use This Checklist
Start with scope. If the wrong services are mapped, the rest of the program may be aimed at the wrong work.
For each item, ask to see the evidence. A policy may say that a task is done. A file, report or system record should show that it was done.
- Step 1
Mark what is complete
Tick an item only when the control is in use and evidence can be found.
- Step 2
Name the gap
For each unticked item, write down what is missing, who owns it and when it will be fixed.
- Step 3
Check the highest risks first
Work that could lead to missed CDD, missed reports or unmanaged high-risk customers should be dealt with first.
If the business cannot show how a control works, it should not be treated as complete.
Part 3
Evidence That Should Be Easy to Find
A clear evidence set makes internal checks, an independent evaluation and an AUSTRAC request easier to manage.
- The current risk assessment, AML/CTF policies and approval records.
- A list of designated services and the facts used to confirm scope.
- Compliance officer, governing body and senior manager records.
- Customer files, risk ratings, monitoring alerts and decision notes.
- Suspicious matter escalation records and filing receipts.
- Training, personnel due diligence and attendance records.
- Program reviews, independent evaluation reports and action logs.
- A record-retention schedule and proof that access is restricted.
Part 4
Key Timing Rules
Some duties must be met before a service starts. Others run for as long as the business is regulated.
- Step 1
Before a designated service starts
A current risk assessment and approved AML/CTF policies should be in place. Initial CDD should be completed unless a lawful delay applies.
- Step 2
When enrolment details change
AUSTRAC must usually be told within 14 days. New reporting entities must apply to enrol within the time set by the Act.
- Step 3
When the business changes
The risk assessment and policies should be reviewed before a planned change, or as soon as possible after an unplanned change.
- Step 4
At least every three years
The full risk assessment and policies must be reviewed. An independent evaluation must also be completed at least this often.
Part 5
Common Mistakes
- A generic program is adopted without being matched to the business.
- Scope is decided from the industry name instead of the service.
- A risk rating is recorded without reasons or source material.
- CDD is completed at onboarding but ongoing CDD is missed.
- Staff are trained once and no check is made that the process is understood.
- Suspicious activity is discussed too widely inside the business.
- Updates are made in practice but the written program is left unchanged.
- An independent evaluation is treated as a document review only.
Helpful answers
Common Questions
Short answers to the questions businesses ask most often.
Does every reporting entity need an AML/CTF program?
Yes. The program must include an ML/TF risk assessment and AML/CTF policies. It must suit the nature, size and complexity of the business.
How long must Australian AML/CTF records be kept?
Many program, CDD and transaction records must be kept for seven years. The point at which the seven years starts depends on the type of record.
How often must the program be reviewed?
The whole risk assessment and all AML/CTF policies must be reviewed at least every three years. Earlier review is required when set events or changes occur.
How often is an independent evaluation required?
It must be done at a frequency that suits the business and at least once every three years. Transitional timing can affect the first evaluation after the reforms.
Is a completed checklist proof of compliance?
No. Evidence must show that each duty has been met and that each control works in practice. Sector and service rules may add further duties.
Do all businesses need to register as well as enrol?
No. Most reporting entities only enrol. A remittance service provider or virtual asset service provider may also need registration.
Reference
Official Sources
This guide cites the following sources.
- Regulator guidanceAUSTRACYour obligations
Current overview of governance, programs, CDD, reporting and record keeping.
- Regulator guidanceAUSTRACDevelop your AML/CTF program
AUSTRAC’s five-step program process and record-keeping guidance.
- Primary lawFederal Register of LegislationAnti-Money Laundering and Counter-Terrorism Financing Act 2006
The current Act, including program, enrolment, reporting and record duties.
- Regulator guidanceAUSTRACRecord keeping checklist
Practical checks for complete, secure and accessible AML/CTF records.