Independent AML/CTF Evaluations in Australia
A practical guide to Australian AML/CTF independent evaluation timing, independence, scope, testing, reports and remediation.
How this guide was researched and reviewedOn this page
Short answer
An independent evaluation checks whether the AML/CTF program meets the law, suits the business and works in practice. It must be completed at a suitable frequency and at least once every three years.
Transitional rules can affect the first evaluation after the 1 July 2026 reforms. The due date should be checked and recorded rather than assumed.
At a glance
A Useful Evaluation Does Four Things
Checks design
The risk assessment and policies are compared with the law and the business.
Tests operation
Files, systems, reports and staff practice are tested, not just read.
Explains impact
Findings show the risk, evidence, cause and action needed.
Confirms repair
Actions are tracked and important fixes are tested after completion.
Plain English
Key Words Explained
These words are used in the law and official guidance. This is what they mean on this page.
- Independent evaluator
- A suitable person who can assess the program objectively and is free from conflicts that would affect the work.
- Design effectiveness
- Whether the control, if followed, is capable of meeting its purpose.
- Operating effectiveness
- Whether the control was actually used, used consistently and produced the intended result.
- Finding
- A clear statement of a gap or weakness supported by evidence.
- Remediation
- The work used to correct a finding and deal with its cause and impact.
Part 1
Set the Timing and Independence
- Complete an evaluation at least every three years and more often when the nature, size, complexity or risk calls for it.
- Check the transitional due date for the first evaluation under the reformed regime.
- Record why the chosen frequency is suitable.
- Check the evaluator’s skills, experience, objectivity and conflicts.
- Make sure the evaluator did not create or operate the controls they are being asked to judge in a way that undermines independence.
- Agree direct access to records, staff and governance before work starts.
Part 2
Set a Risk-Based Scope
- Step 1
Understand the business
Map designated services, locations, systems, customer groups, material changes and known issues.
- Step 2
Check the framework
Assess governance, the risk assessment and the full set of AML/CTF policies against current duties.
- Step 3
Test important controls
Sample customer files, monitoring, reports, training, personnel checks, records and changes. Use larger or targeted samples where risk is higher.
- Step 4
Follow the evidence
Expand testing when a failure may be widespread, serious or linked to a missed report or unmanaged high-risk customer.
Part 3
What the Report Should Contain
| Element | What it should explain | Why it matters |
|---|---|---|
| Requirement | The law, rule, policy or expected control | Shows the benchmark used |
| Evidence | What was reviewed and what was found | Makes the conclusion traceable |
| Impact | The compliance and ML/TF risk created | Helps leaders set priority |
| Cause | Why the problem happened | Stops a surface-only fix |
| Action | What should change, who owns it and by when | Turns the finding into work |
Part 4
Close the Loop
- Assign an owner, due date and priority to each finding.
- Deal first with possible missed reporting, failed CDD and unmanaged high-risk exposure.
- Assess whether customers, transactions or earlier decisions need a look-back.
- Update the risk assessment and policies when the findings affect them.
- Record the updated program within the required period after a change.
- Test important fixes rather than closing them on a promise or new document alone.
Part 5
Common Mistakes
- The evaluation is treated as a legal checklist only.
- The sample contains only easy or low-risk files.
- The evaluator cannot access staff, systems or reporting records.
- Findings describe a problem but not its evidence or risk.
- A policy is rewritten without fixing the workflow or system.
- Actions are marked complete without follow-up testing.
Helpful answers
Common Questions
Short answers to the questions businesses ask most often.
How often is an independent evaluation required?
At a frequency suitable for the business and at least once every three years. Earlier work may be appropriate after major change or serious findings.
Can an employee perform the evaluation?
Independence depends on the facts, not only whether the person is internal or external. They must be able to act objectively and should not evaluate their own work.
Is a document review enough?
Usually not. The evaluator should test implementation and effectiveness using files, systems, reports, interviews and other evidence.
Who should receive the report?
It should reach the people with authority to understand the risk, approve resources and make sure findings are fixed, including the relevant governing body and senior managers.
Must every finding be fixed in the same way?
No. The response should be proportionate to the legal and ML/TF risk. A different action may be chosen if it properly deals with the issue and the reason is recorded.
Reference
Official Sources
This guide cites the following sources.
- Primary lawFederal Register of LegislationAnti-Money Laundering and Counter-Terrorism Financing Act 2006
The current Australian AML/CTF Act, including program, CDD, reporting, governance and record-keeping duties.
- Regulator guidanceAUSTRACStep 5: Conduct an independent evaluation
Current requirements for frequency, independence, scope, reporting and follow-up.
- Regulator guidanceAUSTRACDevelop your AML/CTF program
The five-part process for governance, risk assessment, policies, review and independent evaluation.