Every business providing designated services under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (‘AML/CTF Act‘) — from banks and casinos to lawyers and real estate agents — must maintain a documented, risk-based AML/CTF program before handling a single transaction. The amended Act now requires an outcomes-focused framework that identifies, mitigates and manages money laundering, terrorism financing and proliferation financing (ML/TF/PF) risks.
For Tranche 2 professions facing the 1 July 2026 compliance deadline, building a program that satisfies the Australian Transaction Reports and Analysis Centre‘s (AUSTRAC) expectations is an immediate priority. Civil penalties for non-compliance reach up to 100,000 penalty units for body corporates.
AML/CTF Program Readiness Checker
Quickly check if your business meets the latest AML/CTF program requirements under the updated Australian regime.
Does your business provide any designated services under the AML/CTF Act?
Have you documented and implemented a risk-based AML/CTF program that covers all required components?
Has your AML/CTF program been independently evaluated within the last 3 years?
✅ No AML/CTF Program Required
Reference: Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Speak to a Lawyer about your compliance obligations⚠️ Uncertain AML/CTF Status – Get Legal Guidance
Reference: Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Get AML/CTF Legal Advice❌ Immediate Risk: No AML/CTF Program in Place
Reference:Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Get Urgent AML/CTF Program Legal Advice⚠️ AML/CTF Program Needs Independent Evaluation
Reference: Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Book an AML/CTF Independent Evaluation✅ AML/CTF Program Likely Compliant
Reference: Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Speak to a Lawyer about ongoing AML/CTF complianceUnderstanding AML/CTF Programs & Why They Matter
What is an AML/CTF Program
Under the AML/CTF Act, an AML/CTF program is a comprehensive written framework that identifies, mitigates and manages the risks of ML/TF/PF. Every reporting entity must:
- document this program;
- obtain senior manager approval; and
- have it in place before providing any designated service.
The 2026 reforms shifted the regime from a prescriptive model to an outcomes-based framework. The former mandatory separation into Part A and Part B has been removed. Businesses can now structure their program flexibly, provided all substantive components are addressed, including:
- risk assessment;
- customer due diligence;
- governance;
- training;
- reporting; and
- independent review.
Civil Penalties & Regulatory Consequences of Non-Compliance
The AML/CTF Act introduces civil penalty provisions reaching up to 100,000 penalty units for body corporates that fail to meet their AML/CTF program obligations. Specific contraventions attracting penalties include:
- failure to document a program;
- failure of the program to cover mandated requirements; and
- failure to notify the governing body of program changes.
Operating without a program — or having a written program that is not operationally followed — is a contravention of the AML/CTF Act, providing no compliance protection in an AUSTRAC review, making it essential to seek guidance from experienced AML/CTF lawyers. The obligation to maintain and comply with a program applies from the moment a business provides its first designated service.
Which AUSTRAC Regulated Entities Need an AML/CTF Program
Existing Reporting Entities & Their Designated Services
Several established sectors have been required to maintain an AML/CTF program under the AML/CTF Act for years. These existing reporting entities include:
- financial institutions such as banks, credit unions and building societies;
- remittance dealers;
- virtual asset exchange providers;
- gambling and gaming operators including casinos, pubs and clubs with gaming machines;
- bullion dealers; and
- lenders.
Since 31 March 2026, these entities have been required to operate under the updated outcomes-based framework. The current regime:
- provides program structure flexibility;
- requires enhanced risk assessments that incorporate proliferation financing;
- mandates stronger governance and board oversight; and
- demands updated policies and controls aligned with each business’s actual money laundering and terrorism financing risk profile.
Tranche 2 Professions & the 1 July 2026 Compliance Deadline
The Tranche 2 reforms expanded the AML/CTF regime to designated non-financial businesses and professions (DNFBPs). The following professions are now captured, bringing approximately 100,000 additional entities into the regulated sector:
- lawyers;
- accountants;
- real estate agents;
- conveyancers;
- trust and company service providers; and
- dealers in precious metals and stones.
AUSTRAC enrolment for these professions opened on 31 March 2026, and the full compliance deadline passed on 1 July 2026. Every Tranche 2 entity must now have the following in place and operational:
- risk assessments;
- customer due diligence procedures;
- reporting mechanisms; and
- staff training programs.
No further transitional relief remains available for these businesses.
How to Build an AML/CTF Program
Confirm Your Designated Services & Appoint a Compliance Officer
The first practical step is identifying every designated service your business provides under the AML/CTF Act. Your program only needs to cover designated services, but it must cover all of them. Understating your services is itself a compliance risk if AUSTRAC reviews your program against actual activities.
An AML/CTF compliance officer must be appointed in writing before the program is finalised. This person must:
- be senior;
- have access to all records; and
- have their name, title, and responsibilities documented in the program.
AUSTRAC must be notified of the appointment within 14 days. For sole traders, the owner fills this role.
Complete Your ML/TF Risk Assessment
The ML/TF risk assessment is the foundational step that shapes every other part of the program. Every control must be traceable to a risk identified here, and AUSTRAC checks that traceability directly.
Assess risks across the following categories using a documented methodology:
- client types;
- services;
- delivery channels; and
- jurisdictions.
Assign risk ratings — Low, Medium or High — and evaluate both likelihood and consequence. The assessment must document findings and receive senior manager approval before proceeding to policy development.
Develop AML/CTF Policies, CDD Procedures & a Procedures Manual
The risk management document sets out:
- your governance structure;
- training requirements;
- transaction monitoring procedures;
- enhanced customer due diligence triggers;
- the program review schedule; and
- the independent evaluation timeline.
The CDD procedures document covers:
- customer identification and verification for individuals, companies, trusts and SMSFs;
- simplified, standard and enhanced CDD thresholds and triggers;
- beneficial ownership identification; and
- ongoing CDD review cycles.
A procedures manual operationalises these policies with detailed step-by-step instructions, ensuring consistency and informing employee training content. Existing reporting entities should consider developing new policy documents rather than adapting pre-existing Part A and Part B policies.
Obtain Senior Management Approval, Train Staff & Implement the Program
The program must receive documented senior manager approval — including the approver’s name, title, date and signature — before any designated service is provided. All staff involved in designated services must complete induction training before client-facing work begins, with annual refresher training thereafter covering program content, red flag indicators, CDD procedures and suspicious matter reporting obligations. Training records must be retained for 7 years.
Implementation means:
- conducting CDD on every relevant client;
- monitoring transactions;
- escalating suspicious matters through the compliance officer; and
- submitting suspicious matter reports and threshold transaction reports as required.
Schedule the mandatory independent evaluation.
The Components Every AML/CTF Program Must Address
The ML/TF Risk Assessment as the Foundation of Your Program
The ML/TF risk assessment is the foundation of every AML/CTF program. Under the AML/CTF Act, it must identify and evaluate ML/TF risks — now including proliferation financing — across:
- customer types;
- services;
- delivery channels;
- geographic exposure;
- transaction patterns; and
- AI systems.
The assessment evaluates likelihood and consequence, and every control must be traceable to a risk identified here. Reviews are required at least annually or upon material change, and all reviews must be documented and approved by a senior manager. Material changes include:
- new services;
- new client types;
- FATF listing changes; or
- ownership changes.
Customer Due Diligence Across Simplified, Standard & Enhanced Tiers
Initial CDD requires collecting and verifying KYC information for individuals, companies, trusts and SMSFs. The framework operates across three tiers under the AML/CTF Act:
- Simplified CDD — permitted only where risk is genuinely low, requiring compliance officer approval.
- Standard CDD — the default, requiring full legal name, date of birth or ACN/ABN, and address verified through government ID, ASIC records or the Document Verification Service.
- Enhanced CDD — triggered by PEPs, FATF high-risk jurisdictions, anonymous transactions or complex beneficial ownership, requiring senior management approval and source-of-funds documentation.
Ongoing CDD follows risk-proportionate review cycles, while transaction monitoring detects unusual behaviour through automated or manual systems. Third-party reliance is permitted where the third party has appropriate measures to comply with your obligations.
Reporting Obligations, Record-Keeping & Independent Review
Reporting entities must maintain procedures for:
- Suspicious Matter Reports (SMRs);
- Threshold Transaction Reports (TTRs);
- International Value Transfer Service (IVTS) reports (which replaced IFTI reports under the AML/CTF Act);
- cross-border movement reports; and
- annual compliance reports.
The modernised tipping-off offence targets prejudicial disclosures, and the gambling CDD exemption threshold has been reduced from $10,000 to $5,000.
All of the following must be retained for 7 years, stored securely and access-controlled:
- program documents;
- risk assessments;
- CDD records;
- transaction records;
- SMRs;
- TTRs; and
- training records.
An independent evaluation must be conducted at least every 3 years by a suitably qualified person not involved in day-to-day operations. The evaluation must assess:
- design adequacy;
- control effectiveness;
- operational alignment; and
- identified gaps.
Governance, Compliance Officers & Keeping Your Program Current
Board Oversight, Senior Management Approval & the Compliance Officer Role
Under the AML/CTF Act, a reporting entity’s governing body must take an active role in overseeing ML/TF/PF risk and compliance. The program and risk assessment must receive documented approval from a senior manager, as discussed above.
Every reporting entity must appoint a fit and proper AML/CTF compliance officer to coordinate day-to-day compliance. This role carries specific reporting obligations:
- the compliance officer must report to the governing body at least once every 12 months.
The amended Act also replaces the previous designated business group concept with reporting groups, allowing related entities to meet their AML/CTF obligations collectively.
Staff Training, Program Maintenance & Using AUSTRAC Starter Kits
Personnel due diligence requires specifying which roles perform AML/CTF functions and assessing integrity, including background checks where appropriate. Training must be role-specific, regularly delivered and documented, covering:
- obligations;
- red flag indicators;
- internal processes; and
- escalation protocols.
Training content must also be reviewed and updated to reflect new risks or regulatory changes.
The program must be reviewed and updated when certain triggers occur, including:
- changes to laws or the accompanying rules;
- the introduction of new services or customers; or
- changes to risk profiles.
AUSTRAC starter kits, released in December 2025, provide a useful starting framework but require customisation to reflect actual services, the compliance officer’s name, client types and risk profile. A document that reads as a generic template is a red flag in a compliance review.
Conclusion
An AML/CTF program is mandatory for every business providing designated services — from banks and casinos to Tranche 2 professions including lawyers, accountants, and real estate agents. A compliant program must include a risk assessment, customer due diligence procedures, reporting mechanisms, staff training, governance oversight, and independent review at least every three years.
With the 1 July 2026 Tranche 2 compliance deadline now passed, businesses yet to implement a program face immediate enforcement risk. Contact Click Legal today to speak with a senior lawyer about building an AML/CTF program that reflects your actual services and risk profile.