How to Build an Australian AML/CTF Program
A plain-English guide to building, approving, using and reviewing an Australian AML/CTF program under the rules in force from 1 July 2026.
How this guide was researched and reviewedOn this page
Short answer
An AML/CTF program is the system a reporting entity uses to understand its risks and meet its duties. It combines the ML/TF risk assessment with the policies, procedures, systems and controls used in daily work.
The program must suit the nature, size and complexity of the business. A generic document that is not matched to real services, customers and systems is unlikely to be enough.
At a glance
The Program Has Four Jobs
Describe the risk
The risk assessment should explain where and how the business could be misused.
Set the response
Policies should turn each important risk and legal duty into a clear way of working.
Show ownership
The governing body, senior manager and compliance officer should know what each is responsible for.
Stay current
The program should be reviewed when the business changes and at least every three years.
Plain English
Key Words Explained
These words are used in the law and official guidance. This is what they mean on this page.
- AML/CTF program
- The risk assessment and AML/CTF policies that work together to manage the business’s ML/TF risks and legal duties.
- AML/CTF policies
- The written procedures, systems and controls used to manage risk and comply with the law.
- Governing body
- The person or group with primary responsibility for the business’s governance and executive decisions.
- Senior manager
- A person with authority to approve the program and make important AML/CTF decisions.
- Control
- A practical safeguard, such as a CDD step, approval, alert, report or access restriction.
Part 1
What the Program Must Cover
The program should be one connected system. The risk assessment explains the problem. The policies explain what will be done about it.
- Governance, approval, oversight and the compliance officer’s role.
- Personnel due diligence and role-based AML/CTF training.
- Initial, ongoing, simplified and enhanced customer due diligence.
- Customer risk ratings, monitoring and unusual activity reviews.
- Suspicious matter and other regulatory reporting.
- Targeted financial sanctions and politically exposed person checks.
- Records, privacy, access controls and retention.
- Review, independent evaluation and remediation.
The post-reform program is not split into the old Part A and Part B structure. The risk assessment and AML/CTF policies now form one program.
Part 2
Build It in the Right Order
- Step 1
Confirm the services in scope
List each designated service and how it is delivered. Record the legal item, the Australian link and any exemption relied on.
- Step 2
Assess the risks
Assess the customers, countries, services, delivery channels, transactions and technology that could create ML/TF risk.
- Step 3
Design the controls
For each risk and duty, decide who acts, what they do, when they do it, what evidence is kept and who approves an exception.
- Step 4
Connect the systems
Build the controls into onboarding, case management, payments, monitoring, staff training and management reporting.
- Step 5
Approve and launch
A senior manager must approve the program. Staff should then be trained and given the forms, access and time needed to use it.
Part 3
What Good Evidence Looks Like
A program is easier to defend when a reviewer can follow a straight line from risk to control to result.
| Area | Useful evidence | Question to ask |
|---|---|---|
| Scope | Service map and legal reasoning | Can each designated service be identified? |
| CDD | Completed files, checks and approvals | Can the customer and beneficial owners be understood? |
| Monitoring | Alerts, reviews and closed-case reasons | Are unusual patterns found and dealt with? |
| Reporting | Decision notes and submission receipts | Can the timing and basis of each decision be proved? |
| Governance | Written reports, minutes and action logs | Are leaders informed and are problems fixed? |
Part 4
Review and Update the Program
The full risk assessment and all AML/CTF policies must be reviewed at least every three years. A review may be needed sooner when a service, customer base, country exposure, delivery channel, system, ownership structure or law changes.
Planned changes should be assessed before they are introduced. An unplanned change should be assessed as soon as practical. The reason, decision, approval and version history should be recorded.
When a risk changes, check the policy. When a policy changes, check training, forms, systems and monitoring. Updating only one document can leave a control gap.
Part 5
Common Mistakes
- A template is adopted without being matched to the business.
- The scope list does not match the services staff actually provide.
- Responsibilities are named but no time, authority or backup is provided.
- CDD forms collect information that no one reviews or uses.
- A change is made in practice but the written program is not updated.
- The program is reviewed as a document rather than tested as a working system.
Helpful answers
Common Questions
Short answers to the questions businesses ask most often.
Does a small business need a full AML/CTF program?
Yes, if it is a reporting entity. The program can be simpler when the business is small and less complex, but it must still cover the applicable duties and risks.
Who approves the program?
A senior manager must approve the program. The governing body oversees compliance, and the compliance officer coordinates day-to-day work.
Must the program exist before a designated service starts?
Yes. A current risk assessment and approved AML/CTF policies should be in place before the reporting entity begins providing the designated service.
How often must the program be reviewed?
The full program must be reviewed at least every three years and earlier when relevant changes or findings require it.
Can AUSTRAC’s starter kit be used?
It can be a useful starting point for a business that fits the kit’s suitability criteria. It still needs to be checked, customised, approved, implemented and maintained.
Reference
Official Sources
This guide cites the following sources.
- Primary lawFederal Register of LegislationAnti-Money Laundering and Counter-Terrorism Financing Act 2006
The current Australian AML/CTF Act, including program, CDD, reporting, governance and record-keeping duties.
- Regulator guidanceAUSTRACDevelop your AML/CTF program
The five-part process for governance, risk assessment, policies, review and independent evaluation.
- Regulator guidanceAUSTRACYour obligations
AUSTRAC’s current overview of the duties that apply to reporting entities.
- Regulator guidanceAUSTRACStep 5: Conduct an independent evaluation
Current requirements for frequency, independence, scope, reporting and follow-up.