On this page
- Short answer
- At a glance
- Part 1: Australian AML/CTF Calendar
- Part 2: New Zealand AML/CFT Calendar
- Part 3: A Simple Internal Rhythm
- Part 4: How to Turn This Page Into Your Calendar
- Common questions
- Official sources
Short answer
Good AML compliance is not a once-a-year task. Some duties happen before a service begins, some follow a fixed reporting window, and others are triggered by a customer, transaction, business change or new risk.
Add the dates that apply to your business. A regulator notice, sector rule, exemption or reporting-group arrangement may change the timing.
At a glance
What to Know First
Put fixed dates in the calendar
Add annual reporting windows, training dates, governance meetings and the next independent review.
Create trigger-based tasks
A new service, high-risk customer, unusual activity or control failure should start a defined workflow.
Name an owner
Every task needs a person responsible, a due date and evidence of completion.
Review the calendar
Check it at least quarterly and whenever the law, guidance or business changes.
Part 1 • Australia
Australian AML/CTF Calendar
Australian AML/CTF planning calendar| When | Task | Evidence to keep |
|---|
| Before providing a covered service | Confirm scope, appoint the right people, assess risk, approve the AML/CTF program and prepare customer controls. | Scope note, appointments, approvals, current risk assessment and policies. |
|---|
| Within 28 days after starting | Apply to enrol where the business has started providing a designated service. | Application, confirmation and supporting scope record. |
|---|
| Within 14 days after enrolment | Notify AUSTRAC of the AML/CTF compliance officer. | Appointment record and AUSTRAC notification confirmation. |
|---|
| When a customer is onboarded | Complete the customer, beneficial-owner and acting-person checks required for the risk and service. | Information, verification, risk rating, approvals and any enhanced checks. |
|---|
| When suspicion or a reportable transaction arises | Escalate, decide and submit the required report within the legal timeframe. | Internal escalation, decision record, report receipt and protected supporting material. |
|---|
| When the business or risk changes | Review and, if needed, update the risk assessment and AML/CTF policies. | Change assessment, updated documents, approval, communication and training. |
|---|
| 1 July to 30 September | Submit the annual AUSTRAC compliance report for the previous 1 July to 30 June period. | Working papers, approval and submission receipt. |
|---|
| At least every 3 years | Complete an independent evaluation on the risk-based frequency set in the AML/CTF policies. | Independence and suitability record, scope, testing, report and remediation plan. |
|---|
Part 2 • New Zealand
New Zealand AML/CFT Calendar
New Zealand AML/CFT planning calendar| When | Task | Evidence to keep |
|---|
| Before carrying on a covered activity | Confirm reporting-entity status, complete the risk assessment and programme, appoint the compliance officer and prepare customer controls. | Scope note, current documents, appointment and senior-manager approval. |
|---|
| When a customer is onboarded | Complete standard, simplified or enhanced CDD as required before establishing the relationship or completing the activity, subject to lawful exceptions. | Identity and verification records, beneficial ownership, acting authority, risk rating and approvals. |
|---|
| No later than 3 working days after suspicion forms | Submit a suspicious activity report to the FIU through goAML. | Escalation, decision, SAR receipt and protected supporting material. |
|---|
| When a prescribed transaction occurs | Submit the required prescribed transaction report within the applicable timeframe. | Transaction data, report and submission receipt. |
|---|
| When the business or risk changes | Review the risk assessment and programme and update them where needed. | Change record, updated documents, approval, communication and training. |
|---|
| When DIA opens the annual return process | Complete the annual report or return information requested by the supervisor. | Working papers, approval and submission confirmation. |
|---|
| Generally every 3 years | Obtain an independent AML/CFT audit unless DIA has told the business that a four-year period or another time applies, or a different rule applies. | Independence record, audit scope, testing, report and remediation tracking. |
|---|
Part 3 • Useful rhythm
A Simple Internal Rhythm
- Step 1
Each month
Check overdue CDD, high-risk reviews, unusual activity, report quality, data issues and open remediation actions.
- Step 2
Each quarter
Give leaders a short view of risk, reports, breaches, training, quality checks and important changes.
- Step 3
Each year
Refresh the training plan, test selected controls, review the program or programme and confirm the independent-review date.
- Step 4
After a major change
Do not wait for the next calendar date. Review risk and controls when a product, service, country, system, customer type or law changes.
Part 4 • Set it up
How to Turn This Page Into Your Calendar
- List each legal, regulatory and internal task that applies to the business.
- Add the actual due date or the event that starts the clock.
- Give each task one accountable owner and a backup person.
- Add an earlier internal deadline for review and approval.
- Link the task to the evidence that proves it was completed.
- Review overdue items and changes at a regular governance meeting.
Helpful answers
Common Questions
Short answers to the questions businesses ask most often.
Are all AML deadlines annual?
No. Many duties are continuous or event-driven. Customer checks, suspicious reporting, risk changes and remediation should not wait for an annual review.
How often should the risk assessment be reviewed?
Review it on the cycle set by the business and whenever a material change or new risk could affect it. The right frequency depends on the nature, size, complexity and risk of the business.
How often is independent review required?
Australia requires independent evaluation at least every three years, with transitional rules affecting some first deadlines. New Zealand generally requires an independent audit every three years unless DIA specifies another period or a different rule applies.
Can the compliance officer own every task?
The compliance officer can coordinate the framework, but operational teams, leaders and the governing body also need clear responsibilities. One person should not become the only control.
Should we rely on this page for a legal deadline?
Use it as a planning guide, then confirm the current law, regulator guidance and any notice or exemption that applies to your business.
Reference
Official Sources
This page cites the following sources.
Primary lawFederal Register of Legislation
Regulator guidanceAUSTRAC
Regulator guidanceAUSTRAC
Regulator guidanceAUSTRAC
Primary lawNew Zealand Legislation
Regulator guidanceNew Zealand Police Financial Intelligence Unit
Regulator guidanceDepartment of Internal Affairs