Test and improve • AustraliaRead the New Zealand version

Independent AML/CTF Evaluations in Australia

A practical guide to Australian AML/CTF independent evaluation timing, independence, scope, testing, reports and remediation.

How this guide was researched and reviewed
On this page
  1. Short answer
  2. A Useful Evaluation Does Four Things
  3. Key words explained
  4. Part 1: Set the Timing and Independence
  5. Part 2: Set a Risk-Based Scope
  6. Part 3: What the Report Should Contain
  7. Part 4: Close the Loop
  8. Part 5: Common Mistakes
  9. Common questions
  10. Official sources

Short answer

An independent evaluation checks whether the AML/CTF program meets the law, suits the business and works in practice. It must be completed at a suitable frequency and at least once every three years.

Transitional rules can affect the first evaluation after the 1 July 2026 reforms. The due date should be checked and recorded rather than assumed.

At a glance

A Useful Evaluation Does Four Things

  • Checks design

    The risk assessment and policies are compared with the law and the business.

  • Tests operation

    Files, systems, reports and staff practice are tested, not just read.

  • Explains impact

    Findings show the risk, evidence, cause and action needed.

  • Confirms repair

    Actions are tracked and important fixes are tested after completion.

Plain English

Key Words Explained

These words are used in the law and official guidance. This is what they mean on this page.

Independent evaluator
A suitable person who can assess the program objectively and is free from conflicts that would affect the work.
Design effectiveness
Whether the control, if followed, is capable of meeting its purpose.
Operating effectiveness
Whether the control was actually used, used consistently and produced the intended result.
Finding
A clear statement of a gap or weakness supported by evidence.
Remediation
The work used to correct a finding and deal with its cause and impact.

Set the Timing and Independence

  • Complete an evaluation at least every three years and more often when the nature, size, complexity or risk calls for it.
  • Check the transitional due date for the first evaluation under the reformed regime.
  • Record why the chosen frequency is suitable.
  • Check the evaluator’s skills, experience, objectivity and conflicts.
  • Make sure the evaluator did not create or operate the controls they are being asked to judge in a way that undermines independence.
  • Agree direct access to records, staff and governance before work starts.

Set a Risk-Based Scope

  1. Step 1

    Understand the business

    Map designated services, locations, systems, customer groups, material changes and known issues.

  2. Step 2

    Check the framework

    Assess governance, the risk assessment and the full set of AML/CTF policies against current duties.

  3. Step 3

    Test important controls

    Sample customer files, monitoring, reports, training, personnel checks, records and changes. Use larger or targeted samples where risk is higher.

  4. Step 4

    Follow the evidence

    Expand testing when a failure may be widespread, serious or linked to a missed report or unmanaged high-risk customer.

What the Report Should Contain

A clear finding structure
ElementWhat it should explainWhy it matters
RequirementThe law, rule, policy or expected controlShows the benchmark used
EvidenceWhat was reviewed and what was foundMakes the conclusion traceable
ImpactThe compliance and ML/TF risk createdHelps leaders set priority
CauseWhy the problem happenedStops a surface-only fix
ActionWhat should change, who owns it and by whenTurns the finding into work

Close the Loop

  • Assign an owner, due date and priority to each finding.
  • Deal first with possible missed reporting, failed CDD and unmanaged high-risk exposure.
  • Assess whether customers, transactions or earlier decisions need a look-back.
  • Update the risk assessment and policies when the findings affect them.
  • Record the updated program within the required period after a change.
  • Test important fixes rather than closing them on a promise or new document alone.

Common Mistakes

  • The evaluation is treated as a legal checklist only.
  • The sample contains only easy or low-risk files.
  • The evaluator cannot access staff, systems or reporting records.
  • Findings describe a problem but not its evidence or risk.
  • A policy is rewritten without fixing the workflow or system.
  • Actions are marked complete without follow-up testing.

Common Questions

Short answers to the questions businesses ask most often.

How often is an independent evaluation required?

At a frequency suitable for the business and at least once every three years. Earlier work may be appropriate after major change or serious findings.

Can an employee perform the evaluation?

Independence depends on the facts, not only whether the person is internal or external. They must be able to act objectively and should not evaluate their own work.

Is a document review enough?

Usually not. The evaluator should test implementation and effectiveness using files, systems, reports, interviews and other evidence.

Who should receive the report?

It should reach the people with authority to understand the risk, approve resources and make sure findings are fixed, including the relevant governing body and senior managers.

Must every finding be fixed in the same way?

No. The response should be proportionate to the legal and ML/TF risk. A different action may be chosen if it properly deals with the issue and the reason is recorded.

Official Sources

This guide cites the following sources.

  1. Primary lawFederal Register of Legislation
    Anti-Money Laundering and Counter-Terrorism Financing Act 2006

    The current Australian AML/CTF Act, including program, CDD, reporting, governance and record-keeping duties.

  2. Regulator guidanceAUSTRAC
    Step 5: Conduct an independent evaluation

    Current requirements for frequency, independence, scope, reporting and follow-up.

  3. Regulator guidanceAUSTRAC
    Develop your AML/CTF program

    The five-part process for governance, risk assessment, policies, review and independent evaluation.

This guide provides general information. It is not legal advice and does not account for every exception, exemption or fact pattern.

Need advice for your situation?

Turn the Guidance Into a Clear Next Step.

Tell us what your Australia business does and where the uncertainty sits. We will help you work out the practical AML/CTF response.

Tell us about your situation