In short
An AML/CTF Program is the mandatory document under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) that a reporting entity must maintain, comprising Part A (systems and controls for identifying, mitigating and managing money laundering and terrorism financing risk) and Part B (customer identification and verification procedures). With the Tranche 2 reforms extending reporting entity status to lawyers, accountants, real estate agents and other 'tranche 2' businesses from 2026, many organisations need one for the first time.
Part A: the risk-based framework AUSTRAC actually audits
Part A has to start with a genuine ML/TF risk assessment specific to the reporting entity's customer types, products and services, delivery channels and jurisdictions of operation — not a generic risk statement borrowed from an industry template. AUSTRAC's compliance reports repeatedly criticise programs where the risk assessment doesn't actually drive the controls that follow: a business that identifies high cash-intensity or offshore customer risk in its assessment but then applies the same standard due diligence to every customer regardless of risk rating has a program that fails on its own logic, independent of any actual laundering having occurred.
We build Part A around the entity's real risk profile — its ongoing customer due diligence triggers, enhanced due diligence procedures for higher-risk customers and politically exposed persons, transaction monitoring rules calibrated to actual transaction patterns rather than industry defaults, and the suspicious matter reporting (SMR) escalation pathway with named decision-makers and documented timeframes consistent with the obligation to report as soon as practicable and no later than three business days (or immediately for terrorism financing suspicion).
Part B: customer identification that survives an audit
Part B sets out the applicable customer identification procedures (ACIP) for each customer type the entity deals with — individuals, companies, trusts, partnerships and government bodies each require different documentary or electronic verification standards under the AML/CTF Rules. We draft Part B to reflect the entity's actual onboarding channels: a business onboarding customers only in person needs a different verification workflow to one onboarding entirely digitally through electronic verification providers, and a program that describes a process the business doesn't actually run through its onboarding system is a common finding in AUSTRAC reviews.
Tranche 2: what changes for lawyers, accountants and real estate agents
The AML/CTF Amendment Act 2024 extends reporting entity obligations to a defined set of 'tranche 2' services — including certain legal, accounting, real estate and trust and company services — with a compliance start date that gives affected businesses a transition window to build a program from scratch. For many of these businesses, this is the first time they've had to draw a line between 'designated services' captured by the Act (such as managing client money or property, or acting as a formation agent) and the rest of their practice, which is a threshold scoping exercise before Part A and Part B can even be drafted. We work through the designated services analysis first, because getting the scope wrong either over-captures work that doesn't need a program or leaves a genuine gap in coverage.
Governance, independent review and the AML/CTF compliance officer
The Act requires a designated AML/CTF compliance officer with sufficient authority and resourcing, board or senior management approval of the program, an ongoing employee due diligence and training program, and an independent review of the program at a frequency appropriate to the entity's risk profile. We draft the governance and independent review clauses to be specific about who reviews, how often, and what triggers an out-of-cycle review, because 'periodic review' without a defined interval is a standard audit finding.
What we deliver
A Part A risk assessment and control framework and a Part B customer identification procedure genuinely built around the entity's business, a designated services scoping memo for tranche 2 entrants, and a governance structure naming the compliance officer's authority and the independent review cycle.
What the fixed fee covers
- ML/TF risk assessment specific to customer, product, channel and jurisdiction risk
- Part A systems and controls including SMR escalation pathway
- Part B applicable customer identification procedures by customer type
- Designated services scoping memo (for tranche 2 entrants)
- AML/CTF compliance officer governance structure
- Independent review cycle and employee due diligence and training framework
Mistakes we see
- Risk assessment that doesn't actually drive the level of due diligence applied to different customer risk ratings
- Part B describing verification steps the onboarding system doesn't actually perform
- No defined interval or trigger for independent program review
- Tranche 2 entities failing to properly scope which services are 'designated services' before drafting the program
- SMR escalation pathway with no named decision-maker or documented timeframe
Who this is for
- Existing AUSTRAC reporting entities due for a program review
- Fintechs, remittance providers and digital currency exchanges
- Law firms, accounting practices and real estate agencies preparing for Tranche 2
- Businesses expanding into new customer segments or jurisdictions
Frequently asked questions
- When do Tranche 2 obligations actually start?
- The AML/CTF Amendment Act 2024 sets a transition period for newly captured tranche 2 businesses, with compliance obligations phasing in from 2026. We recommend affected businesses start the designated services scoping exercise well ahead of the compliance start date, because building a defensible risk assessment and Part B procedure from a standing start under time pressure produces weaker programs.
- Does every business need both Part A and Part B?
- Yes, if the entity provides a designated service and is therefore a reporting entity, both parts are mandatory; there's no reduced-scope version for smaller entities, though the level of detail and complexity in the program should be proportionate to the entity's size and risk profile.
- What triggers a suspicious matter report?
- A reasonable suspicion connected to money laundering, terrorism financing, proceeds of crime, tax evasion or certain other offences, formed by any officer or employee, not just the compliance officer. The obligation to report arises on forming the suspicion, so the escalation pathway needs to move quickly regardless of who first identifies the concern.
- Can we outsource customer identification to a third-party verification provider?
- Yes, electronic verification through an accredited provider is common and permitted under the AML/CTF Rules, but the reporting entity remains legally responsible for the adequacy of identification performed on its behalf, so the program needs to document the reliance arrangement and the entity's own oversight of the provider.
- What happens if AUSTRAC finds our program inadequate?
- Outcomes range from a remediation direction and enforceable undertaking through to civil penalty proceedings for serious or systemic failures, and AUSTRAC has shown a willingness to pursue significant penalties against reporting entities with materially deficient programs, so a paper-only program that doesn't reflect actual practice carries real financial risk.
Related
