Two parts, not three
The Act says an AML/CTF program "comprises: (a) the reporting entity's ML/TF risk assessment; and (b) the reporting entity's AML/CTF policies".1 That is the whole structure.
- The risk assessment identifies and assesses the risks of money laundering, terrorism financing and proliferation financing your firm may reasonably face in providing its designated services. s 26C
- The policies are your "policies, procedures, systems and controls" for managing those risks and meeting your obligations. s 26F
Governance is not a separate part. The compliance officer, the governing body's information and the approvals are matters your policies must deal with.2 Both parts must suit the nature, size and complexity of your business, so a small practice can have a short, plain program.3
Old guides, old structure
Material written before the reforms describes a program in Part A and Part B. That structure was repealed in March 2026 and never applied to firms regulated from 1 July 2026. A template that still uses it probably carries old section numbers too.4
Part one: the risk assessment
In your risk assessment you must have regard to the kinds of services you provide or plan to provide, the kinds of clients, how you deliver the services, the countries you deal with, information AUSTRAC gives you about your risks, and any matters in the Rules.5
Three rules sit around it:
- You must not start providing a designated service to a client unless your risk assessment meets these requirements. s 26E
- You must review it when something significant changes, when AUSTRAC tells you about new risks, and in any event at least once every 3 years. s 26D
- A senior manager must approve it and every update. s 26P
Our risk assessment guide walks through the method AUSTRAC describes, step by step.
Part two: the policies
Your policies must manage and mitigate the risks your assessment identifies, make sure you meet your obligations under the Act and the Rules, and suit the size of your business.6 The Act and the Rules then list the matters they must deal with. This is the checklist for a policy document.
| Matter | What it means for a small firm | Law |
|---|---|---|
| Significant changes | How you spot a change to your services, clients, channels or countries, so you can review the risk assessment. | s 26F(3)(a) |
| Customer due diligence | When you collect, or collect and verify, each kind of client information at the start and during the relationship, including source of wealth and source of funds. | s 26F(3)(b) Rules 5-2 |
| Sanctions | Making sure you do not make assets available to, or deal with assets of, a person designated for targeted financial sanctions. | Rules 5-3 |
| Approvals | Getting a senior manager's approval before acting in the cases listed in the next section. | Rules 5-5 |
| Keeping the policies current | Reviewing and updating them after a risk-assessment review, after an evaluation with adverse findings, and in any event at least once every 3 years. | s 26F(3)(c) s 26F(3)(d) Rules 5-4 |
| Governing body | Giving the governing body the information it needs to oversee your risks, unless your business is an individual. | s 26F(4)(a) Rules 5-6 |
| Compliance officer reports | The compliance officer reporting to the governing body at least once every 12 months, unless one person holds both roles. | Rules 5-7 |
| Roles | Designating the compliance officer, and the senior manager or managers who approve the risk assessment and the policies. | s 26F(4)(b) s 26F(4)(c) |
| Staff checks | Assessing the skills, knowledge, expertise and integrity of people in AML/CTF roles, before they start and while they work for you. | s 26F(4)(d) Rules 5-8 |
| Training | Initial and ongoing training suited to each person's function, risks and responsibilities, and readily understandable. | s 26F(4)(e) Rules 5-9 |
| Independent evaluation | How often your program is independently evaluated (at least once every 3 years) and how you respond to the report. | s 26F(4)(f) Rules 5-10 |
| Accurate reports | Making sure what you report to AUSTRAC is complete, accurate and free from unauthorised change. | Rules 5-11 |
| Possible suspicious matters | Reviewing relevant material in time and deciding as soon as practicable whether you have a suspicion to report. | Rules 5-12 |
| Tipping off | Safeguards so that nobody in the firm tips off a client about a suspicious matter report. | Rules 5-13 |
| Real estate settlements | For an agent or conveyancer relying on another business under Rules 6-33: how you verify client information before settlement if you do not receive it. | Rules 5-20 |
Proliferation financing. You do not need separate policies for proliferation financing if you reasonably assess that risk as low and your money laundering and terrorism financing policies manage it appropriately. If you rely on this, the burden of showing it is on you, so record your reasons in the risk assessment.7
Approvals your policies must require
Your policies must make sure a senior manager approves the step before you:8
- start acting for a client if the client, a beneficial owner, or a person the client acts for is a foreign politically exposed person (always);
- start acting where that person is a domestic or international organisation politically exposed person and the client's risk is high;
- enter a written agreement to rely on another business's client identification and verification under s 37A.
If an existing client becomes a politically exposed person in those circumstances, a senior manager must decide whether you continue.8 For politically exposed persons you must also establish their source of wealth and source of funds: always for a foreign one, and for a domestic or international organisation one where the risk is high.9
The sanctions policy must refer to the Autonomous Sanctions Act 2011 and the Charter of the United Nations Act 1945, which the Rules name.10 We have not summarised how those Acts work. AUSTRAC points businesses to the lists published by the Department of Foreign Affairs and Trade on its risk assessment page.
Tipping off
It is an offence to disclose that a suspicious matter report has been, or must be, made, where the disclosure would or could reasonably be expected to prejudice an investigation. The penalty is imprisonment for 2 years or 120 penalty units, or both.11 Your policies must set out the safeguards that stop this happening.12
Lawyers and qualified accountants have a narrow exception. They may disclose information about a client's affairs in good faith to dissuade the client from conduct that is, or could be, an offence.11 It is an exception to the offence, not a general permission to discuss a report.
Who does what
Governing body
Oversees how the firm identifies and assesses its risks and whether it complies with its policies and the law, and takes reasonable steps to make sure it does. If your business is an individual, that individual is the governing body. s 26H s 5
Compliance officer
Oversees day-to-day compliance and speaks to AUSTRAC for the firm. Must be employed or engaged at management level, with enough authority and resources, a resident of Australia and a fit and proper person. Designate one within 28 days of your first designated service and notify AUSTRAC within 14 days of designating them. s 26J s 26K s 26L s 26M Rules 5-14
Senior manager
Approves the risk assessment, the policies and every update. The governing body must be told in writing of each update to the risk assessment as soon as practicable. s 26P
In a small practice one person may hold all three roles. Where the compliance officer is the same individual as the governing body, or the business is an individual, the Rules 5-7 reports to the governing body do not apply.13
Write it down before your first client
You must document your risk assessment and your policies before you first provide a designated service to a customer. Each later update must be documented within 14 days.14 You must not start providing a designated service until your policies exist, and once they exist you must follow them.15 AUSTRAC can ask for the documents.16
Independent evaluation
Your program must be independently evaluated at least once every 3 years. The evaluation covers the steps you took in your risk assessment, the design of your policies, whether you follow them, and whether you are managing your risks. The evaluator gives a written report to your governing body and to the senior manager who approves the program.17
For firms whose enrolment was due on 29 July 2026, the first evaluation must happen before a date set by the last two digits of the enrolment identifier.18
| Last two digits of your enrolment identifier | Evaluate before |
|---|---|
| Both odd (for example 35) | 30 June 2029 |
| Odd, then even (for example 36) | 31 December 2029 |
| Both even (for example 46) | 30 June 2030 |
| Even, then odd (for example 47) | 31 December 2030 |
Because we write program documents, we do not carry out independent evaluations. The set-up service plans the evaluation with you and you choose the evaluator.
The free option: AUSTRAC's starter kits
AUSTRAC publishes free program starter kits for accountants, conveyancers, jewellers, the legal profession and real estate. The release we checked is 1.1, dated 10 June 2026.19 Each kit has suitability criteria. For the accountant and real estate kits they include 15 or fewer personnel, mostly Australian-resident individual clients, no overseas property, no fully remote self-service options and not being part of a large reporting group. For a practice outside the profile, the accountant kit says "you cannot rely on the starter kit to meet AUSTRAC's regulatory expectations of an appropriate AML/CTF program for your practice". AUSTRAC also says its guidance "isn't a substitute for legal advice".20 Check the criteria for your sector on AUSTRAC's program starter kits page before you choose.
AUSTRAC links on this page open in a new window. AUSTRAC has not reviewed or endorsed this guide.
Where we fit
- Your sector: accounting practices, real estate agencies, conveyancers and legal practices.
- The documents: our kit is built on AUSTRAC's starter kits. The risk assessment, the policies and the approval record are documents 02, 03 and 24, with the section behind each obligation written in.
- Set-up with us: the set-up service works through your program with you. We do not act as your compliance officer or senior manager.
- More: the risk assessment guide, the other guides and every source we use on the sources page.
Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.
Sources
Law is quoted from the authorised text on the Federal Register of Legislation, opened 25 September 2026. AUSTRAC pages are guidance, not law.
-
AML/CTF Act s 26B. legislation.gov.au/C2006A00169/latest/text
-
AML/CTF Act s 26F(4)(a)–(c).
-
AML/CTF Act ss 26C(2) and 26F(1)(c).
-
AML/CTF Amendment Act 2024 (C2024A00110), Schedule 1, item 30, and s 2 (commencement of Schedule 1); Schedule 3, item 11. legislation.gov.au/C2024A00110/latest/text
-
AML/CTF Act s 26C(1) and (3).
-
AML/CTF Act s 26F(1).
-
AML/CTF Act s 26F(11) and (12).
-
AML/CTF Rules 2025 (F2025L01026), rule 5-5(1) and (1A). legislation.gov.au/F2025L01026/latest/text
-
AML/CTF Rules 2025, rules 6-23 and 6-24.
-
AML/CTF Rules 2025, rule 5-3.
-
AML/CTF Act s 123(1), (2) and (4).
-
AML/CTF Rules 2025, rule 5-13.
-
AML/CTF Rules 2025, rule 5-7(3).
-
AML/CTF Act s 26N; AML/CTF Rules 2025, rule 5-15.
-
AML/CTF Act ss 26F(8) and 26G.
-
AML/CTF Act s 26Q.
-
AML/CTF Act s 26F(4)(f); AML/CTF Rules 2025, rule 5-10.
-
AML/CTF Transitional Rules 2026 (F2026L00393), s 17. legislation.gov.au/F2026L00393/latest/text
-
AUSTRAC, "Program starter kits" and "Updates to the accountant program starter kit", read 25 September 2026. Guidance, not law.
-
AUSTRAC, "Accounting program starter kit: Getting started" and "Real estate program starter kit: Getting started", read 25 September 2026. Guidance, not law. © AUSTRAC for the Commonwealth of Australia 2026, CC BY 4.0.