Practical guide • AustraliaRead the New Zealand version

Australian AML/CTF Compliance Checklist

Use this free on-page checklist to see which core AML/CTF duties have been dealt with and what may still need work.

How this guide was researched and reviewed
On this page
  1. Short answer
  2. Start With These Four Questions
  3. Key words explained
  4. Part 1: Core checklist
  5. Part 2: How to Use This Checklist
  6. Part 3: Evidence That Should Be Easy to Find
  7. Part 4: Key Timing Rules
  8. Part 5: Common Mistakes
  9. Common questions
  10. Official sources

Short answer

A reporting entity needs more than a written policy. Its scope, people, risk assessment, customer checks, reporting, records and review process must all work together.

This checklist covers the main duties for reporting entities. Extra duties can apply to a sector, service, reporting group or transaction.

At a glance

Start With These Four Questions

  • Is the scope written down?

    Each designated service and its link to Australia should be recorded.

  • Is the program in use?

    The risk assessment and AML/CTF policies should guide real work, not sit on a shelf.

  • Can the work be proved?

    Records should show customer checks, decisions, reports, training and review.

  • Is it kept current?

    Changes to services, customers, countries, systems and risk should be picked up.

Plain English

Key Words Explained

These words are used in the law and official guidance. This is what they mean on this page.

AML/CTF
Rules that help stop money laundering, terrorism financing and proliferation financing.
Reporting entity
A business or person that must follow AML/CTF rules for a service it provides.
Designated service
A service named in section 6 of the Australian AML/CTF Act.
CDD
Customer due diligence. These are checks used to know the customer and understand their risk.
SMR
Suspicious matter report. This is sent to AUSTRAC when the legal test for suspicion is met.
Independent evaluation
A check by a suitable independent person to see whether the AML/CTF program meets the rules and works.

Work Through the Core Duties

Tick an item only when it has been completed and evidence can be shown. Your progress stays in this browser and is not saved.

Progress0/13

Nothing has been marked complete yet.

How to Use This Checklist

Start with scope. If the wrong services are mapped, the rest of the program may be aimed at the wrong work.

For each item, ask to see the evidence. A policy may say that a task is done. A file, report or system record should show that it was done.

  1. Step 1

    Mark what is complete

    Tick an item only when the control is in use and evidence can be found.

  2. Step 2

    Name the gap

    For each unticked item, write down what is missing, who owns it and when it will be fixed.

  3. Step 3

    Check the highest risks first

    Work that could lead to missed CDD, missed reports or unmanaged high-risk customers should be dealt with first.

A useful rule

If the business cannot show how a control works, it should not be treated as complete.

Evidence That Should Be Easy to Find

A clear evidence set makes internal checks, an independent evaluation and an AUSTRAC request easier to manage.

  • The current risk assessment, AML/CTF policies and approval records.
  • A list of designated services and the facts used to confirm scope.
  • Compliance officer, governing body and senior manager records.
  • Customer files, risk ratings, monitoring alerts and decision notes.
  • Suspicious matter escalation records and filing receipts.
  • Training, personnel due diligence and attendance records.
  • Program reviews, independent evaluation reports and action logs.
  • A record-retention schedule and proof that access is restricted.

Key Timing Rules

Some duties must be met before a service starts. Others run for as long as the business is regulated.

  1. Step 1

    Before a designated service starts

    A current risk assessment and approved AML/CTF policies should be in place. Initial CDD should be completed unless a lawful delay applies.

  2. Step 2

    When enrolment details change

    AUSTRAC must usually be told within 14 days. New reporting entities must apply to enrol within the time set by the Act.

  3. Step 3

    When the business changes

    The risk assessment and policies should be reviewed before a planned change, or as soon as possible after an unplanned change.

  4. Step 4

    At least every three years

    The full risk assessment and policies must be reviewed. An independent evaluation must also be completed at least this often.

Common Mistakes

  • A generic program is adopted without being matched to the business.
  • Scope is decided from the industry name instead of the service.
  • A risk rating is recorded without reasons or source material.
  • CDD is completed at onboarding but ongoing CDD is missed.
  • Staff are trained once and no check is made that the process is understood.
  • Suspicious activity is discussed too widely inside the business.
  • Updates are made in practice but the written program is left unchanged.
  • An independent evaluation is treated as a document review only.

Common Questions

Short answers to the questions businesses ask most often.

Does every reporting entity need an AML/CTF program?

Yes. The program must include an ML/TF risk assessment and AML/CTF policies. It must suit the nature, size and complexity of the business.

How long must Australian AML/CTF records be kept?

Many program, CDD and transaction records must be kept for seven years. The point at which the seven years starts depends on the type of record.

How often must the program be reviewed?

The whole risk assessment and all AML/CTF policies must be reviewed at least every three years. Earlier review is required when set events or changes occur.

How often is an independent evaluation required?

It must be done at a frequency that suits the business and at least once every three years. Transitional timing can affect the first evaluation after the reforms.

Is a completed checklist proof of compliance?

No. Evidence must show that each duty has been met and that each control works in practice. Sector and service rules may add further duties.

Do all businesses need to register as well as enrol?

No. Most reporting entities only enrol. A remittance service provider or virtual asset service provider may also need registration.

Official Sources

This guide cites the following sources.

  1. Regulator guidanceAUSTRAC
    Your obligations

    Current overview of governance, programs, CDD, reporting and record keeping.

  2. Regulator guidanceAUSTRAC
    Develop your AML/CTF program

    AUSTRAC’s five-step program process and record-keeping guidance.

  3. Primary lawFederal Register of Legislation
    Anti-Money Laundering and Counter-Terrorism Financing Act 2006

    The current Act, including program, enrolment, reporting and record duties.

  4. Regulator guidanceAUSTRAC
    Record keeping checklist

    Practical checks for complete, secure and accessible AML/CTF records.

This guide provides general information. It is not legal advice and does not account for every exception, exemption or fact pattern.

Need advice for your situation?

Turn the Guidance Into a Clear Next Step.

Tell us what your Australia business does and where the uncertainty sits. We will help you work out the practical AML/CTF response.

Tell us about your situation