What the law requires
Your AML/CTF program is two things: your ML/TF risk assessment and your AML/CTF policies.1 The policies must deal with the conduct of independent evaluations of that program, including how often they happen. The frequency must be appropriate to the nature, size and complexity of your business, and at least once every 3 years.2 You must then comply with your own policies, and that duty is a civil penalty provision.3 So an evaluation your policies promise, and you do not carry out, is a breach.
Act s 51B the law, read in the authorised textAUSTRAC guidance the regulator's published guidance
The Act and the Rules call it an independent evaluation s 26F(4)(f) Rules 5-10. Older material says "independent review", the term used before the 2024 amendments to the Act took effect. Use the current term in your policies.
The evaluation is separate from your own reviews. You review the risk assessment when a trigger occurs and at least once every 3 years s 26D, and review your policies at least once every 3 years s 26F(3)(d). AUSTRAC says the independent evaluation is "in addition to" those reviews.4
What the evaluation must cover
Your policies must require each of these as part of every independent evaluation:5
The risk assessment steps
Evaluation of the steps you took when undertaking or reviewing your risk assessment, against the Act, the regulations and the Rules. Rules 5-10
The design of your policies
Evaluation of the design of your AML/CTF policies, against the same requirements. Rules 5-10
Compliance testing
Testing and evaluation of whether you comply with your own policies. Rules 5-10
Effectiveness
Testing and evaluation of whether you are appropriately identifying, assessing, managing and mitigating your money laundering, terrorism financing and proliferation financing risks. Rules 5-10
A written report
An independent evaluation report with findings on each of the four matters above. Rules 5-10
Delivery
The report goes to your governing body and to any senior manager responsible for approvals under s 26P. Rules 5-10 s 26P
Your policies must also say how you will respond to the report.6
When it is due
Your first evaluation, if the 29 July 2026 enrolment rule applied to you. That rule covered firms that were already providing a real estate or professional service (or a Table 2 item 2 dealer service) before 1 July 2026 and no other designated service.7 For those firms, the first evaluation meets the frequency requirement in your policies if it is carried out before the date that matches the last two digits of your enrolment identifier:8
| Last two digits of your enrolment identifier | Evaluate before |
|---|---|
| Both odd (for example 35) | 30 June 2029 |
| Odd, then even (for example 36) | 31 December 2029 |
| Both even (for example 46) | 30 June 2030 |
| Even, then odd (for example 47) | 31 December 2030 |
If you started providing designated services on or after 1 July 2026, this table does not apply. Your first and later evaluations follow the frequency in your own policies, which must be at least once every 3 years.2
Setting the frequency. AUSTRAC expects you to record why you chose your frequency, including the features of your business's nature, size and complexity that led to the decision. It also suggests newly enrolled firms consider an earlier first evaluation, so problems are found and fixed sooner, and because evaluators with the right skills may be easier to find.4
Who can carry it out
The Act and the Rules do not name a qualification. AUSTRAC says there are "no mandatory qualifications", and sets out what it expects.4
Independence. The evaluator must be free of bias, influence and conflicts of interest. They can be internal, such as a member of an internal audit team, or external. AUSTRAC expects the evaluator to:
- have the authority to exercise independent judgement, and be free to conduct the evaluation as they see fit;
- not be responsible for implementing or maintaining the program;
- not have been involved in developing your program, systems and controls, or in assessing your risks; and
- be independent of the work they evaluate, so not your compliance officer or a member of the compliance team.
Suitability. AUSTRAC expects the evaluator to know the AML/CTF obligations that apply to you and the risks businesses in your sector face. It suggests considering their experience with similar businesses, their experience evaluating controls and writing up findings, any AML/CTF qualifications, and whether they belong to a professional body that sets relevant standards. It expects your policies to say how you will decide that an evaluator is both independent and suitable.
In a practice where one person wrote the program and runs it, that person cannot be the evaluator, so in practice the evaluator comes from outside the firm. That is our reading of AUSTRAC's independence expectations.
How to prepare
AUSTRAC expects you to give the evaluator access to documents, key people and systems. It says the evaluator may ask for documents on how you developed your risk assessment and policies, access to staff and senior managers, customer identification and transaction records, the results of your own monitoring and reviews, and previous evaluation reports.4
Most of that already exists if your program runs as the law requires. Before the evaluation, gather:
- the program as documented, with each version and its senior-manager approval s 26N s 26P Rules 5-15;
- your risk assessment reviews, and what triggered each one s 26D;
- the compliance officer's reports to the governing body, if your firm is not a one-person practice Rules 5-7;
- customer due diligence files the evaluator can sample, including any enhanced due diligence s 28 s 32;
- your training and personnel due diligence records s 26F(4)(d) s 26F(4)(e);
- your reporting records, such as any suspicious matter or threshold transaction reports s 41 s 43.
AUSTRAC warns that failing to give the evaluator proper access makes the evaluation less reliable and increases the risk that your program does not meet your obligations.4
The report and your response
AUSTRAC expects the governing body and relevant senior managers to receive the report as soon as reasonably practicable after it is prepared. It says a report will typically summarise the process and method, give findings on the risk assessment, the policy design and your compliance, and describe what was tested and sampled.4
If the report has adverse findings about your risk assessment, you must review it as soon as practicable after the governing body receives the report.9 Your policies must also deal with reviewing and updating the policies in response to adverse findings about the policies.10 Any update must be approved by a senior manager, and the program as updated documented within 14 days.11
AUSTRAC says you do not have to agree with every adverse finding, but expects you to take them seriously and to record how you addressed each one, including your reasons where you decided not to change the program. It also expects you to check afterwards that the changes worked.4
Keep the record
You must keep records reasonably necessary to show you complied with the program obligations.12 AUSTRAC's examples for the evaluation include the evaluation report, the files that were sampled, discussions of the findings with senior managers and the governing body, why you chose the evaluator, how you addressed each finding and who was responsible.4
AUSTRAC's page Step 5: Conduct an independent evaluation has the full detail. AUSTRAC links on this page open in a new window. AUSTRAC has not reviewed or endorsed this guide.
Where we fit
We do not carry out independent evaluations, and we cannot evaluate a program we helped write. What we do is help you plan one.
- The free option: AUSTRAC publishes free program starter kits, which include a step for maintaining and reviewing your program.
- Your sector: accounting practices, real estate agencies, conveyancers and legal practices.
- The documents: our kit is built on AUSTRAC's starter kits. Document 22 is an independent evaluation plan and response form, and document 18 is a calendar dated for your firm, including the first evaluation.
- Set-up with us: in the set-up service we work out your first evaluation date from your enrolment identifier and give you an evaluation plan. You choose and engage the evaluator.
- More: every tranche 2 date is in our key dates guide. See also the other guides and every source we use on the sources page.
Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.
Sources
Law is quoted from the authorised text on the Federal Register of Legislation, opened 25 September 2026. AUSTRAC pages are guidance, not law.
-
AML/CTF Act s 26B. legislation.gov.au/C2006A00169/latest/text
-
AML/CTF Act s 26F(4)(f).
-
AML/CTF Act s 26G(1) and (3).
-
AUSTRAC, "Step 5: Conduct an independent evaluation", last updated by AUSTRAC in March 2026, read 25 September 2026. Guidance, not law. © AUSTRAC for the Commonwealth of Australia 2026, CC BY 4.0.
-
AML/CTF Rules 2025 (F2025L01026), rule 5-10(2). legislation.gov.au/F2025L01026/latest/text
-
AML/CTF Rules 2025, rule 5-10(3).
-
AML/CTF Amendment Act 2024 (C2024A00110), Schedule 3, item 12(1). legislation.gov.au/C2024A00110/latest/text
-
AML/CTF Transitional Rules 2026 (F2026L00393), s 17(1)–(2). legislation.gov.au/F2026L00393/latest/text
-
AML/CTF Rules 2025, rule 5-1; AML/CTF Act s 26D.
-
AML/CTF Rules 2025, rule 5-4.
-
AML/CTF Act s 26P(1); AML/CTF Rules 2025, rule 5-15(2).
-
AML/CTF Act s 116(1).