Obligations

The AML/CTF program: risk assessment, policies, templates and the annual review

The AML/CTF program is the document AUSTRAC asks for first. Under the reformed regime it has two parts: a money laundering and terrorism financing risk assessment of your business, and the policies and procedures you use to manage that risk. Here is what goes in it and how a small firm produces one without a consultant.

Updated 23 Sept 2026

A bound trust deed with a navy cover and ribbon on a walnut desk, beside reading glasses.

Part one: the risk assessment

An honest description of how your business could be used to launder money, considering your customers (who they are, where they are, whether any are politically exposed), your services, how you deliver them (face to face or remotely) and the jurisdictions involved. The output is a rating of your inherent risk and a list of the factors that drive it.

Part two: the policies

  • Customer due diligence: what you collect, how you verify, when you apply enhanced due diligence.
  • Ongoing monitoring and periodic reviews by risk level.
  • Reporting: how a staff member escalates a concern and how the compliance officer lodges reports within the deadlines.
  • Record keeping for seven years.
  • Staff training and screening.
  • Governance: the compliance officer, senior management approval, and how the program is reviewed and independently evaluated.

Templates: useful, with one warning

A template gets the structure right and saves days. The risk is adopting it unchanged: a program that describes a firm that is not yours is worse than a short one that is. Answer a questionnaire about your own business, generate the document from those answers, read it, change what does not fit, and then adopt it. Each sister site offers a sample program for its sector and a tool that generates one from your answers.

Approval, review and independent evaluation

Senior management must approve the program. It must be kept current: reviewed whenever your services, clients or the law change and at regular intervals; a yearly review is common practice. The reformed Rules also require an independent evaluation of the program at set intervals, which for a small firm can be done by a suitably skilled person who did not write it.

Questions people ask

Do I still need Part A and Part B?
No. The reformed regime replaced the Part A/Part B structure with a single program built on a risk assessment and policies. Existing entities had to restructure by 31 March 2026.
How long should a small firm's program be?
Long enough to describe your actual risks and procedures, usually ten to fifteen pages. Length is not compliance; accuracy is.
Who can do the independent evaluation?
Someone independent of the program's design and operation with the skills to assess it. It does not have to be an external consultant, but it cannot be the compliance officer evaluating their own work.

General information about Australian AML/CTF law, not legal advice. The Act, the Rules and AUSTRAC's guidance are the primary sources.

The AML/CTF program: risk assessment, policies, templates and the annual review · AML/CTF Guide