Updated August 2026

Reference · The AML/CTF Program

What is an AML/CTF program?

A written framework covering how your business assesses ML/TF risk and verifies customers — required before you provide a single designated service. What it must contain, and how to build one.
Core components
Risk management + CDD
3 yrs
Independent evaluation
7 yrs
Record retention
1 Jul
In effect since

An AML/CTF program is the written framework a reporting entity uses to identify, assess and manage money laundering and terrorism financing risk. It connects the business’s ML/TF risk assessment to governance, customer due diligence, transaction monitoring, staff training, regulatory reporting, record keeping and review. Subject to applicable statutory exemptions, a reporting entity that provides a designated service must have a program appropriate to the nature, size and complexity of its business.

I. The Short Answer

What is an AML/CTF program, and who needs one?

When AUSTRAC refers to your AML/CTF program, it means the complete documented framework — not a single policy document.

AML/CTF Act 2006

III. The Foundation

A ML/TF risk assessment comes first — here's why

Every control in your program has to be traceable to a risk identified here. AUSTRAC checks that traceability directly.

Client-type risk

Individuals, companies, trusts, SMSFs, PEPs, non-residents. Higher-risk types need enhanced controls and more frequent reviews.

Product & service risk

Property transactions, trust formation, precious metals, client fund management — internationally recognised as high risk.

Delivery channel risk

Online-only onboarding, remote transactions, trust accounts, and intermediaries all increase risk vs face-to-face.

Jurisdiction risk

Connections to FATF grey- or black-listed countries. Your assessment must reference current listings and apply enhanced CDD.

The assessment must be reviewed when a specified review trigger occurs and, in any event, at least once every 3 years. Triggers include a significant change to relevant business circumstances, relevant risk information communicated by AUSTRAC, and adverse findings in an independent evaluation report. Any issues identified by the review must be reflected in the risk assessment and affected AML/CTF policies.

Governance and accountability

Who is responsible for the AML/CTF program?

AML/CTF policies must address applicable governance requirements, including the Compliance Officer role, subject to any statutory exemptions that apply to the reporting entity.

The program must be approved by a senior manager before you start providing designated services, subject to any applicable statutory exemptions. Document the approval with the approver’s name, title, date, and signature.

IV. Three Tiers, One Test

Customer due diligence: simplified, standard, enhanced

The tier isn't your choice to make freely — it's set by the risk of the customer and the service in front of you.

I

Simplified CDD

When permitted

Simplified CDD may be used only where the circumstances and requirements specified in the AML/CTF Act and Rules are met.

II

Standard CDD

Risk-based

Initial CDD requirements depend on the customer type, designated service, assessed ML/TF risk, and the information and verification requirements specified in the AML/CTF Act and Rules.

III

Enhanced CDD

When required

Enhanced CDD must be applied when a trigger specified in the AML/CTF Act or Rules applies. The required steps and approvals depend on the applicable trigger.

Reporting, training and monitoring

Put the program into day-to-day operation

Put the program into practice — conduct CDD on every relevant client, monitor transactions, escalate suspicious matters through your Compliance Officer, and submit SMRs and TTRs as required. See how to submit a Suspicious Matter Report to AUSTRAC.

Your AML/CTF policies must provide for initial and ongoing training for personnel who perform functions relevant to the business’s AML/CTF obligations. The training must be appropriate to each person’s function, relevant ML/TF risks, and responsibilities under the policies. Keep training records under the applicable program-record requirements.

Review, updates and independent evaluation

Keep the program current and test how it operates

A reporting entity must review and, where required, update its ML/TF risk assessment and AML/CTF policies when a specified review trigger occurs. Relevant triggers include significant changes, risk information communicated by AUSTRAC, and adverse findings from an independent evaluation. Reviews are also required in any event at least once every 3 years. An updated AML/CTF program must be documented within 14 days after the update occurs.

For reporting entities to which the independent-evaluation requirement applies, AML/CTF policies must provide for an independent evaluation at a frequency appropriate to the nature, size and complexity of the business and at least once every 3 years. The evaluation must assess the entity’s risk-assessment process, policy design, compliance with its policies, and management of ML/TF risk, and it must produce a written report.

AML/CTF program records must be kept until 7 years after they are no longer relevant to demonstrating compliance with Part 1A of the Act. These records can include the current program, relevant previous versions, version history, approval records, and records of reviews or independent evaluations.

V. Building It

Nine steps, in order — each one builds on the last

This is the sequence the HowTo schema on this page follows. Skipping ahead usually means redoing earlier work.

01

Confirm your designated services

Identify every designated service your business provides under the AML/CTF Act. Your program only needs to cover designated services — but it must cover all of them. Understating your services is itself a compliance risk if AUSTRAC reviews your program against your actual activities.

02

Appoint your Compliance Officer in writing

The Compliance Officer must be senior, have access to all records, and be formally appointed before the program is finalised. Their name, title, and responsibilities must appear in the program document. For sole traders, the owner fills this role.

03

Complete your ML/TF risk assessment

Assess your risks across client types, services, delivery channels, and jurisdictions. Assign risk ratings — Low, Medium, or High. Document your methodology and findings. This assessment is the foundation of everything else in the program — every control must be traceable to a risk you identified here.

04

Write your risk management framework

Document your governance structure, training requirements and schedule, transaction monitoring procedures, enhanced due diligence triggers, program review schedule, and independent evaluation timeline. Every control must connect back to a risk identified in your risk assessment. You are not required to label this as a separate 'Part A' — organise it however suits your business.

05

Write your CDD procedures

Document your customer identification and verification procedures for each client type — individuals, companies, trusts, SMSFs. Include simplified, standard, and enhanced CDD thresholds, triggers, and steps. Include your beneficial ownership identification procedure and your ongoing CDD review schedule.

06

Get senior management approval

Mandatory

The program must be approved by a senior manager before you start providing designated services, subject to any applicable statutory exemptions. Document the approval with the approver's name, title, date, and signature.

07

Train your staff

Your AML/CTF policies must provide for initial and ongoing training for personnel who perform functions relevant to the business's AML/CTF obligations. The training must be appropriate to each person's function, relevant ML/TF risks, and responsibilities under the policies. Keep training records under the applicable program-record requirements.

08

Implement and operate the program

Put the program into practice — conduct CDD on every relevant client, monitor transactions, escalate suspicious matters through your Compliance Officer, and submit SMRs and TTRs as required. A written program that is not operationally followed provides no compliance protection and no defence in an AUSTRAC review.

09

Schedule your independent evaluation

At least every 3 yrs

For reporting entities to which the requirement applies, AML/CTF policies must provide for an independent evaluation at a frequency appropriate to the nature, size and complexity of the business and at least once every 3 years. Schedule the evaluation in advance.

II. What Changed in 2024

Do you still need separate Part A and Part B sections?

No. The rigid two-part labelling is gone — but the substance underneath it hasn't moved.

Formerly “Part A”

Risk management framework

ML/TF risk assessment methodology · governance and Compliance Officer role · staff training schedule · transaction monitoring · enhanced CDD triggers · program review schedule · independent evaluation requirements.

Formerly “Part B”

CDD procedures

Customer identification for individuals, companies and trusts · beneficial ownership (25% threshold) · simplified / standard / enhanced CDD · PEP identification · ongoing CDD review · record-keeping.

AUSTRAC’s current guidance lets you organise your program however suits your business, provided it satisfies the Act’s requirements. The two components above still both have to be there — only the mandatory labelling has been dropped.

VI. Starter Kit vs Custom

A generic template and a compliant program aren't the same thing

AUSTRAC’s free sector Starter Kits are a genuine head start — a pre-built framework aligned to official guidance, available at austrac.gov.au ↗. But they’re generic by design — no business name, no compliance officer, no specific designated services, no client risk profile.

When AUSTRAC reviews your program, the regulator looks for evidence it reflects how your business actually operates — not just that a document exists.

AUSTRAC guidance

A document that reads as a generic template for anyone in your sector is a red flag in a compliance review. One that references your actual services, client types, officer name, and risk profile demonstrates genuine intent — that distinction is the whole test.

VII. Keeping the Paper Trail

Record-keeping — different rules for different records

Different AML/CTF record categories have different retention rules. Program records must be retained until 7 years after they are no longer relevant to demonstrating compliance with Part 1A of the Act. CDD, transaction and reporting records are subject to their own retention provisions. Records must be stored securely and remain retrievable.

If AUSTRAC conducts a compliance review, they may request historical versions of the program to assess whether it was genuinely maintained over time — not just written once and filed away.

AML/CTF Act 2006, record-keeping obligations

VIII. Reference

Everything else people ask

Reporting entities generally need an AML/CTF program regardless of size, subject to applicable statutory exemptions. A sole-practitioner conveyancer and a large law firm may both need one. The program must be appropriate to the nature, size and complexity of the reporting entity’s business. Failure to meet applicable program obligations can contravene the Act. Use the penalty calculator to estimate your firm's exposure.

Primary sources

Last updated 20 August 2026 · Klyvon Compliance Team

IX. How Klyvon Helps

Generate your AML/CTF program for review

4–6 questions, one document

Your industry, designated services, client types, and compliance officer — Klyvon generates both the risk framework and CDD procedures in one pass.

Cited throughout

Every section references the AML/CTF Act 2006 by name, written in first person for your firm — not a swapped-logo template.

A starting point, not the finish line

Built on AUSTRAC official guidance. We recommend review by a qualified AML/CTF adviser before operational reliance.

Generate my program — free →

Free to start · cancel anytime

Related resources