Build the foundation • AustraliaRead the New Zealand version

How to Build an Australian AML/CTF Program

A plain-English guide to building, approving, using and reviewing an Australian AML/CTF program under the rules in force from 1 July 2026.

How this guide was researched and reviewed
On this page
  1. Short answer
  2. The Program Has Four Jobs
  3. Key words explained
  4. Part 1: What the Program Must Cover
  5. Part 2: Build It in the Right Order
  6. Part 3: What Good Evidence Looks Like
  7. Part 4: Review and Update the Program
  8. Part 5: Common Mistakes
  9. Common questions
  10. Official sources

Short answer

An AML/CTF program is the system a reporting entity uses to understand its risks and meet its duties. It combines the ML/TF risk assessment with the policies, procedures, systems and controls used in daily work.

The program must suit the nature, size and complexity of the business. A generic document that is not matched to real services, customers and systems is unlikely to be enough.

At a glance

The Program Has Four Jobs

  • Describe the risk

    The risk assessment should explain where and how the business could be misused.

  • Set the response

    Policies should turn each important risk and legal duty into a clear way of working.

  • Show ownership

    The governing body, senior manager and compliance officer should know what each is responsible for.

  • Stay current

    The program should be reviewed when the business changes and at least every three years.

Plain English

Key Words Explained

These words are used in the law and official guidance. This is what they mean on this page.

AML/CTF program
The risk assessment and AML/CTF policies that work together to manage the business’s ML/TF risks and legal duties.
AML/CTF policies
The written procedures, systems and controls used to manage risk and comply with the law.
Governing body
The person or group with primary responsibility for the business’s governance and executive decisions.
Senior manager
A person with authority to approve the program and make important AML/CTF decisions.
Control
A practical safeguard, such as a CDD step, approval, alert, report or access restriction.

What the Program Must Cover

The program should be one connected system. The risk assessment explains the problem. The policies explain what will be done about it.

  • Governance, approval, oversight and the compliance officer’s role.
  • Personnel due diligence and role-based AML/CTF training.
  • Initial, ongoing, simplified and enhanced customer due diligence.
  • Customer risk ratings, monitoring and unusual activity reviews.
  • Suspicious matter and other regulatory reporting.
  • Targeted financial sanctions and politically exposed person checks.
  • Records, privacy, access controls and retention.
  • Review, independent evaluation and remediation.
Important

The post-reform program is not split into the old Part A and Part B structure. The risk assessment and AML/CTF policies now form one program.

Build It in the Right Order

  1. Step 1

    Confirm the services in scope

    List each designated service and how it is delivered. Record the legal item, the Australian link and any exemption relied on.

  2. Step 2

    Assess the risks

    Assess the customers, countries, services, delivery channels, transactions and technology that could create ML/TF risk.

  3. Step 3

    Design the controls

    For each risk and duty, decide who acts, what they do, when they do it, what evidence is kept and who approves an exception.

  4. Step 4

    Connect the systems

    Build the controls into onboarding, case management, payments, monitoring, staff training and management reporting.

  5. Step 5

    Approve and launch

    A senior manager must approve the program. Staff should then be trained and given the forms, access and time needed to use it.

What Good Evidence Looks Like

A program is easier to defend when a reviewer can follow a straight line from risk to control to result.

Examples of evidence that the program is working
AreaUseful evidenceQuestion to ask
ScopeService map and legal reasoningCan each designated service be identified?
CDDCompleted files, checks and approvalsCan the customer and beneficial owners be understood?
MonitoringAlerts, reviews and closed-case reasonsAre unusual patterns found and dealt with?
ReportingDecision notes and submission receiptsCan the timing and basis of each decision be proved?
GovernanceWritten reports, minutes and action logsAre leaders informed and are problems fixed?

Review and Update the Program

The full risk assessment and all AML/CTF policies must be reviewed at least every three years. A review may be needed sooner when a service, customer base, country exposure, delivery channel, system, ownership structure or law changes.

Planned changes should be assessed before they are introduced. An unplanned change should be assessed as soon as practical. The reason, decision, approval and version history should be recorded.

Keep the program connected

When a risk changes, check the policy. When a policy changes, check training, forms, systems and monitoring. Updating only one document can leave a control gap.

Common Mistakes

  • A template is adopted without being matched to the business.
  • The scope list does not match the services staff actually provide.
  • Responsibilities are named but no time, authority or backup is provided.
  • CDD forms collect information that no one reviews or uses.
  • A change is made in practice but the written program is not updated.
  • The program is reviewed as a document rather than tested as a working system.

Common Questions

Short answers to the questions businesses ask most often.

Does a small business need a full AML/CTF program?

Yes, if it is a reporting entity. The program can be simpler when the business is small and less complex, but it must still cover the applicable duties and risks.

Who approves the program?

A senior manager must approve the program. The governing body oversees compliance, and the compliance officer coordinates day-to-day work.

Must the program exist before a designated service starts?

Yes. A current risk assessment and approved AML/CTF policies should be in place before the reporting entity begins providing the designated service.

How often must the program be reviewed?

The full program must be reviewed at least every three years and earlier when relevant changes or findings require it.

Can AUSTRAC’s starter kit be used?

It can be a useful starting point for a business that fits the kit’s suitability criteria. It still needs to be checked, customised, approved, implemented and maintained.

Official Sources

This guide cites the following sources.

  1. Primary lawFederal Register of Legislation
    Anti-Money Laundering and Counter-Terrorism Financing Act 2006

    The current Australian AML/CTF Act, including program, CDD, reporting, governance and record-keeping duties.

  2. Regulator guidanceAUSTRAC
    Develop your AML/CTF program

    The five-part process for governance, risk assessment, policies, review and independent evaluation.

  3. Regulator guidanceAUSTRAC
    Your obligations

    AUSTRAC’s current overview of the duties that apply to reporting entities.

  4. Regulator guidanceAUSTRAC
    Step 5: Conduct an independent evaluation

    Current requirements for frequency, independence, scope, reporting and follow-up.

This guide provides general information. It is not legal advice and does not account for every exception, exemption or fact pattern.

Need advice for your situation?

Turn the Guidance Into a Clear Next Step.

Tell us what your Australia business does and where the uncertainty sits. We will help you work out the practical AML/CTF response.

Tell us about your situation