On-page planning tool • Australia & New Zealand

AML Compliance Calendar for Australia and New Zealand

A practical schedule of the recurring and event-driven AML work that reporting entities should plan for.

How this guide was researched and reviewed
On this page
  1. Short answer
  2. At a glance
  3. Part 1: Australian AML/CTF Calendar
  4. Part 2: New Zealand AML/CFT Calendar
  5. Part 3: A Simple Internal Rhythm
  6. Part 4: How to Turn This Page Into Your Calendar
  7. Common questions
  8. Official sources

Short answer

Good AML compliance is not a once-a-year task. Some duties happen before a service begins, some follow a fixed reporting window, and others are triggered by a customer, transaction, business change or new risk.

Add the dates that apply to your business. A regulator notice, sector rule, exemption or reporting-group arrangement may change the timing.

At a glance

What to Know First

  • Put fixed dates in the calendar

    Add annual reporting windows, training dates, governance meetings and the next independent review.

  • Create trigger-based tasks

    A new service, high-risk customer, unusual activity or control failure should start a defined workflow.

  • Name an owner

    Every task needs a person responsible, a due date and evidence of completion.

  • Review the calendar

    Check it at least quarterly and whenever the law, guidance or business changes.

Australian AML/CTF Calendar

Australian AML/CTF planning calendar
WhenTaskEvidence to keep
Before providing a covered serviceConfirm scope, appoint the right people, assess risk, approve the AML/CTF program and prepare customer controls.Scope note, appointments, approvals, current risk assessment and policies.
Within 28 days after startingApply to enrol where the business has started providing a designated service.Application, confirmation and supporting scope record.
Within 14 days after enrolmentNotify AUSTRAC of the AML/CTF compliance officer.Appointment record and AUSTRAC notification confirmation.
When a customer is onboardedComplete the customer, beneficial-owner and acting-person checks required for the risk and service.Information, verification, risk rating, approvals and any enhanced checks.
When suspicion or a reportable transaction arisesEscalate, decide and submit the required report within the legal timeframe.Internal escalation, decision record, report receipt and protected supporting material.
When the business or risk changesReview and, if needed, update the risk assessment and AML/CTF policies.Change assessment, updated documents, approval, communication and training.
1 July to 30 SeptemberSubmit the annual AUSTRAC compliance report for the previous 1 July to 30 June period.Working papers, approval and submission receipt.
At least every 3 yearsComplete an independent evaluation on the risk-based frequency set in the AML/CTF policies.Independence and suitability record, scope, testing, report and remediation plan.

New Zealand AML/CFT Calendar

New Zealand AML/CFT planning calendar
WhenTaskEvidence to keep
Before carrying on a covered activityConfirm reporting-entity status, complete the risk assessment and programme, appoint the compliance officer and prepare customer controls.Scope note, current documents, appointment and senior-manager approval.
When a customer is onboardedComplete standard, simplified or enhanced CDD as required before establishing the relationship or completing the activity, subject to lawful exceptions.Identity and verification records, beneficial ownership, acting authority, risk rating and approvals.
No later than 3 working days after suspicion formsSubmit a suspicious activity report to the FIU through goAML.Escalation, decision, SAR receipt and protected supporting material.
When a prescribed transaction occursSubmit the required prescribed transaction report within the applicable timeframe.Transaction data, report and submission receipt.
When the business or risk changesReview the risk assessment and programme and update them where needed.Change record, updated documents, approval, communication and training.
When DIA opens the annual return processComplete the annual report or return information requested by the supervisor.Working papers, approval and submission confirmation.
Generally every 3 yearsObtain an independent AML/CFT audit unless DIA has told the business that a four-year period or another time applies, or a different rule applies.Independence record, audit scope, testing, report and remediation tracking.

A Simple Internal Rhythm

  1. Step 1

    Each month

    Check overdue CDD, high-risk reviews, unusual activity, report quality, data issues and open remediation actions.

  2. Step 2

    Each quarter

    Give leaders a short view of risk, reports, breaches, training, quality checks and important changes.

  3. Step 3

    Each year

    Refresh the training plan, test selected controls, review the program or programme and confirm the independent-review date.

  4. Step 4

    After a major change

    Do not wait for the next calendar date. Review risk and controls when a product, service, country, system, customer type or law changes.

How to Turn This Page Into Your Calendar

  • List each legal, regulatory and internal task that applies to the business.
  • Add the actual due date or the event that starts the clock.
  • Give each task one accountable owner and a backup person.
  • Add an earlier internal deadline for review and approval.
  • Link the task to the evidence that proves it was completed.
  • Review overdue items and changes at a regular governance meeting.

Common Questions

Short answers to the questions businesses ask most often.

Are all AML deadlines annual?

No. Many duties are continuous or event-driven. Customer checks, suspicious reporting, risk changes and remediation should not wait for an annual review.

How often should the risk assessment be reviewed?

Review it on the cycle set by the business and whenever a material change or new risk could affect it. The right frequency depends on the nature, size, complexity and risk of the business.

How often is independent review required?

Australia requires independent evaluation at least every three years, with transitional rules affecting some first deadlines. New Zealand generally requires an independent audit every three years unless DIA specifies another period or a different rule applies.

Can the compliance officer own every task?

The compliance officer can coordinate the framework, but operational teams, leaders and the governing body also need clear responsibilities. One person should not become the only control.

Should we rely on this page for a legal deadline?

Use it as a planning guide, then confirm the current law, regulator guidance and any notice or exemption that applies to your business.

Official Sources

This page cites the following sources.

  1. Primary lawFederal Register of Legislation
  2. Regulator guidanceAUSTRAC
    Annual compliance reports

    Current Australian reporting period and submission-window guidance.

  3. Regulator guidanceAUSTRAC
    AML/CTF compliance officer

    Current Australian appointment and notification guidance.

  4. Regulator guidanceAUSTRAC
    Conduct an independent evaluation

    Current Australian independent-evaluation frequency and expectations.

  5. Primary lawNew Zealand Legislation
  6. Regulator guidanceNew Zealand Police Financial Intelligence Unit
    Suspicious Activity and Transaction Reports

    Confirms the three-working-day New Zealand SAR deadline.

  7. Regulator guidanceDepartment of Internal Affairs
    AML/CFT guidance and resources

    Guidance and information for reporting entities supervised by DIA.

This page provides general information. It is not legal advice and does not account for every exception, exemption or fact pattern.

Need a calendar that fits the business?

Turn the Legal Dates Into Work People Can Own.

We can help identify the tasks, triggers, owners and evidence that belong in your AML compliance calendar.

Talk through your compliance cycle