How Often a Business Had to Conduct an AML/CTF Independent Review (Pre‑31 March 2026)

Published By:

Hannah Deuk

Founder & Principal Lawyer

Key Takeaways:

  • No Fixed Statutory Timeframe: Under the legacy AML independent review framework, review frequency had to be determined using a risk-based approach that accounted for the entity’s nature, size, complexity, and ML/TF risk, as mandated by the 2007 AML/CTF Rules.
  • High-Risk Entity Expectations: If an organisation had a higher money laundering or terrorism financing risk profile under the former system, the regulatory expectation was to conduct an independent review every two to three years.
  • Out-of-Cycle Review Triggers: Businesses had to conduct an immediate review outside their regular schedule if they experienced business changes, such as introducing new products, expanding jurisdictions, or facing regulatory actions under the AML/CTF Act (Cth).
  • Individualised Group Cycles: When operating under a joint program under the legacy framework, businesses had to avoid relying on a single group-wide review cycle, as the frequency had to be tailored to the risk profile of each individual reporting entity within the designated business group.
Jump to...
June 3, 2026

Important: Australia’s AML/CTF laws were substantially reformed on 31 March 2026. This article outlines the historical frequency requirements for conducting an AML/CTF independent review under the legacy pre-reform framework.

For details on the rules regarding how often you must perform the new AML independent evaluation (effective from 31 March 2026), please see our current guide on how often you must conduct an AML/CTF independent evaluation.

Introduction

Under the pre-reform AML/CTF independent review framework, reporting entities were required to subject Part A of their anti-money laundering and counter-terrorism financing (AML/CTF) program to a regular independent review. This obligation was established under Rule 8.6/9.6 of the legacy 2007 AML/CTF Rules. These rules did not prescribe a fixed schedule, creating a compliance challenge for businesses that had to determine the timing of their reviews.

This article explains the historical legal standard for the frequency of the independent review under the pre-reform AML/CTF framework. It clarifies how an independent review was conducted at an appropriate interval based on a risk assessment, business changes, and other triggers, enabling compliance professionals to meet their statutory obligations under the pre-reform framework.

Request Free Consultation Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

Frequency of the AML Independent Review Under the Former Framework

Rules 8.6.1 and 9.6.1 of the pre-reform Anti-Money Laundering and Counter-Terrorism Financing Rules Instrument 2007 (No. 1) (Cth) (2007 AML/CTF Rules) mandated that Part A of an AML/CTF program had to be subject to a regular independent review.

This obligation was framed as an ongoing and periodic requirement, meaning it was not satisfied by a single, one-off review. Therefore, reporting entities had to establish a recurring process to help ensure compliance with this rule.

Meaning of “Regular” & Its Risk Assessment Implications

The term “regular” was not defined within the 2007 AML/CTF Rules. Instead of prescribing a fixed schedule, it required a risk-based approach to determine the appropriate frequency of an independent review.

Under Rule 8.6.2/9.6.2 of the 2007 AML/CTF Rules, the frequency of the review had to consider several factors specific to the reporting entity, as follows:

  • the nature, size, and complexity of the business operations; and
  • the type and level of money laundering and terrorism financing (ML/TF) risk the business faced.

These factors made a risk assessment an important part of determining what constituted a “regular” interval for an AML independent review. This structure aimed to ensure that the compliance effort was proportionate to the risks of the entity.

Speak to Our Senior Lawyers Today

Request your free consult & our senior lawyers will contact you to discuss your situation.

Independent Review: What the Law Actually Requires

Annual Reviews are not Mandatory

A common belief was that reporting entities had to conduct an AML independent review on a fixed annual schedule. However, no statutory provision within Rule 8.6/9.6 of the 2007 AML/CTF Rules mandated yearly reviews.

Instead of prescribing a specific cycle for the frequency of independent reviews, the legacy law clarified the following:

  • No set timeframes: There was no legal requirement for a review to occur every 12, 24, or 36 months.
  • Risk-based approach: The obligation was framed around a risk-based assessment rather than a rigid timetable.

Relying on a Single Review or Pure Convenience

The statutory obligation under Rule 8.6.1/9.6.1 of the 2007 AML/CTF Rules required that Part A of an AML/CTF program be subject to “regular independent review.” This established an ongoing duty, meaning a single review conducted once would not satisfy the legal requirement over the long term.

Furthermore, deciding on the frequency of an independent review based purely on convenience or budgetary constraints introduced compliance risk. While those Rules did not expressly prohibit considering these factors, the purpose of the review still had to be met.

Under the 2007 AML/CTF Rules, a purpose was to assess the effectiveness of the program in relation to the entity’s specific ML/TF risk. As a result, a schedule determined by convenience alone could fail to assess this effectiveness adequately, particularly if the business or its risk profile changed.

Request Free Consultation Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

When a Fixed Review Cycle Created Legal Risk

Vulnerability of Static Review Cycles

Under the former framework, relying on a static or fixed timetable to conduct an AML independent review, such as scheduling one every two years without exception, introduced compliance risk. A key danger was that an AML/CTF program could become non-compliant during the interval between reviews.

Furthermore, a fixed cycle did not adapt to shifts in a business’s risk environment. This approach could fail to satisfy the legacy legal standard that the frequency of an independent review had to account for the nature, size, complexity, and ML/TF risk of the entity. Consequently, a program that was appropriate at the last review might no longer have been adequate, leaving the business exposed to the consequences of non-compliance under the former independent review rules.

Rapid Business Change & Untested Known Deficiencies

A fixed review schedule was often problematic for businesses undergoing rapid change. Sticking to a pre-determined date for the next independent review could be inadequate when the business experienced events such as:

  • Entering new regulated activities, for instance, offering cryptocurrency exchange or remittance services;
  • Onboarding new high-risk customer segments; or
  • Introducing new products or designated services.

These changes could alter a business’ AML/CTF risk assessment and render existing controls ineffective.

In addition, risk arose when known deficiencies were left untested. If a prior independent review identified compliance gaps or made recommendations for improvement, waiting for the next scheduled review left those weaknesses unverified. Without a follow-up review to assess the effectiveness of corrective actions, the business could not demonstrate that it had addressed the identified issues.

Speak to Our Senior Lawyers Today

Request your free consult & our senior lawyers will contact you to discuss your situation.

Trigger-Based AML Independent Reviews

Business Changes Prompting an Out-of-Cycle AML Independent Review

Certain business events could require an immediate, out-of-cycle independent review to maintain compliance, even if these triggers were not explicitly listed in the 2007 AML/CTF Rules. Furthermore, a failure to conduct an independent review following operational shifts could undermine the effectiveness of an AML/CTF program.

Triggers that could prompt the need for a new risk assessment and review included:

  • Changes to the AML/CTF program itself;
  • The introduction of new products or designated services;
  • Structural business changes like mergers or acquisitions;
  • Starting to outsource AML/CTF obligations to another entity;
  • Expansion into new jurisdictions; and
  • Updates or changes to core systems, such as transaction monitoring platforms.

Regulatory Actions and Statutory Failure Triggers

Regulatory actions and the discovery of specific compliance failures were clear indicators that an immediate independent review was necessary. As a result, an inquiry or compliance action from the Australian Transaction Reports and Analysis Centre (AUSTRAC) typically prompted a business to assess its program’s effectiveness through a new review.

The identification of certain statutory failures also served as a trigger. These included breaches of obligations under the pre-reform AML/CTF Act, such as:

  • Failures in suspicious matter reporting, as was required by Section 41;
  • Gaps in reporting threshold transactions under Section 43; and
  • Deficiencies in record-keeping obligations outlined in Section 107.

Request Free Consultation Today

Our senior lawyers will contact you to discuss your situation & outline next steps.

Frequency of Independent Review in the Context of Joint Programs

Group-Wide Reviews Versus Entity-Specific Risk

For designated business groups, Part 9.6 of the 2007 AML/CTF Rules governed the requirements for joint AML/CTF programs. Under Rule 9.6.1, Part A of a joint program had to be subject to a regular independent review at the group level.

This created a challenge for compliance. The obligation to conduct an independent review applied to the program as a whole, but the ML/TF risk could vary between individual entities within the group. As a result, this required balancing a group-wide assessment against the risk profiles of each member.

Risks of Applying a Single Review Cycle Across a Designated Business Group

The 2007 AML/CTF Rules did not specify whether a single review cycle was sufficient for all entities operating under a joint program. However, applying one fixed frequency of independent review across an entire designated business group could introduce compliance risk. A uniform cycle could fail to capture differences in risk at the individual entity level.

Furthermore, this approach could breach the requirement under Rule 9.6.2 of the 2007 AML/CTF Rules. This rule mandated that the review frequency had to consider several factors for each reporting entity within the group, as follows:

  • the nature of the entity;
  • the size and complexity of the entity; and
  • the ML/TF risk of the entity.

A single cycle might have been inadequate for a high-risk entity, even if it was appropriate for others.

Speak to Our Senior Lawyers Today

Request your free consult & our senior lawyers will contact you to discuss your situation.

Real Legal Standard for Timing of an AML Independent Review

For compliant independent review timing, a reporting entity had to meet a practical legal test. The central question was whether the business could demonstrate that its AML/CTF program was subject to a regular independent review sufficient to assess its effectiveness and compliance at all relevant times.


Here is the reframed section. The content has been adjusted to the past tense to reflect the legacy framework, the shorthand 2007 AML/CTF Rules and the consolidated reference Rule 8.6/9.6 have been applied, and all external links to the AML/CTF Act and Rules have been removed. The text has also been refined to maintain an objective, professional, and humble tone.


The Historical Legal Standard for Timing of an AML Independent Review

For compliant legacy independent review timing, a reporting entity had to meet a legal test. The central question was whether the business could demonstrate that its AML/CTF program was subject to a regular independent review sufficient to assess its effectiveness and compliance at all relevant times.

This standard was derived from the obligations under Rule 8.6/9.6 of the 2007 AML/CTF Rules. It required more than just conducting a review; it demanded that the frequency of the independent review was adequate to help the program remain effective as the business and its risks evolved.

When assessing this adequacy, a reporting entity had to be able to provide evidence and reasoning based on its specific circumstances. Considerations included:

  • The entity’s risk profile: A business with a higher ML/TF risk was expected to conduct an independent review more frequently than a lower-risk entity.
  • The rate of business change: Businesses that frequently introduced new products, expanded into new jurisdictions, or underwent operational changes needed a shorter review cycle to help their AML/CTF program keep pace.
  • Findings from past reviews: If a previous independent review identified deficiencies or made recommendations for improvement, a follow-up review could be required sooner to verify that corrective actions had been effective.
  • Regulatory exposure: If the entity’s industry was under increased scrutiny, or if the business had prior compliance issues, more frequent reviews could demonstrate a commitment to addressing regulatory concerns.

Conclusion

The frequency of a legacy AML/CTF independent review in Australia was not determined by a fixed schedule but by a risk-based approach specific to each reporting entity. Businesses had to be able to justify the timing of their reviews based on their specific risk profile, the rate of operational change, and any compliance triggers, rather than adhering to a static cycle.

To help ensure your approach to the frequency of compliance assessments meets current requirements, contact the AML independent review & evaluation lawyers at Click Legal for guidance. Our Legal Team offers independent legal evaluations and reviews for AUSTRAC-regulated businesses, helping you maintain compliance under both the legacy framework and the current independent evaluation regime, which officially replaced reviews on 31 March 2026.

Frequently Asked Questions

JUMP TO...
Table of Contents

Published By:

Hannah Deuk

Founder & Principal Lawyer

Request A Free Consultation

Our senior lawyers will contact you to discuss your situation & outline next steps.

Insights Library

Legal & Compliance Insights

Browse practical articles, guides & updates from our lawyers on key legal & compliance issues.

Join our Newsletter

Subscribe to our newsletter for the latest legal updates, insights, and firm news delivered straight to your inbox.

What Our Clients Say About Working With Us

Ready-to-Use Legal & Compliance Templates

Lawyer‑drafted legal templates in downloadable Word format.

CONTACT

Request A Consultation

Not sure which matter or service is right for you? Leave your details & our lawyers will contact you to discuss your situation & outline next steps.

Inquire Now

Tell us briefly what you need help with & we’ll reply within 1 business day.