Guide · general information, not legal advice

What an AML/CTF program must include

Last checked 25 September 2026 against the AML/CTF Act compilation C2026C00274, the AML/CTF Rules 2025 (F2025L01026) and the Transitional Rules 2026 (F2026L00393)

Your AML/CTF program is two things: your ML/TF risk assessment and your AML/CTF policies. This guide lists what each must deal with, who approves it and when it must be written down, with the section of the Act or the Rules behind every item.

Two parts, not three

The Act says an AML/CTF program "comprises: (a) the reporting entity's ML/TF risk assessment; and (b) the reporting entity's AML/CTF policies".1 That is the whole structure.

  • The risk assessment identifies and assesses the risks of money laundering, terrorism financing and proliferation financing your firm may reasonably face in providing its designated services. s 26C
  • The policies are your "policies, procedures, systems and controls" for managing those risks and meeting your obligations. s 26F

Governance is not a separate part. The compliance officer, the governing body's information and the approvals are matters your policies must deal with.2 Both parts must suit the nature, size and complexity of your business, so a small practice can have a short, plain program.3

Old guides, old structure

Material written before the reforms describes a program in Part A and Part B. That structure was repealed in March 2026 and never applied to firms regulated from 1 July 2026. A template that still uses it probably carries old section numbers too.4

Part one: the risk assessment

In your risk assessment you must have regard to the kinds of services you provide or plan to provide, the kinds of clients, how you deliver the services, the countries you deal with, information AUSTRAC gives you about your risks, and any matters in the Rules.5

Three rules sit around it:

  • You must not start providing a designated service to a client unless your risk assessment meets these requirements. s 26E
  • You must review it when something significant changes, when AUSTRAC tells you about new risks, and in any event at least once every 3 years. s 26D
  • A senior manager must approve it and every update. s 26P

Our risk assessment guide walks through the method AUSTRAC describes, step by step.

Part two: the policies

Your policies must manage and mitigate the risks your assessment identifies, make sure you meet your obligations under the Act and the Rules, and suit the size of your business.6 The Act and the Rules then list the matters they must deal with. This is the checklist for a policy document.

What your AML/CTF policies must deal with
Matter What it means for a small firm Law
Significant changes How you spot a change to your services, clients, channels or countries, so you can review the risk assessment. s 26F(3)(a)
Customer due diligence When you collect, or collect and verify, each kind of client information at the start and during the relationship, including source of wealth and source of funds. s 26F(3)(b) Rules 5-2
Sanctions Making sure you do not make assets available to, or deal with assets of, a person designated for targeted financial sanctions. Rules 5-3
Approvals Getting a senior manager's approval before acting in the cases listed in the next section. Rules 5-5
Keeping the policies current Reviewing and updating them after a risk-assessment review, after an evaluation with adverse findings, and in any event at least once every 3 years. s 26F(3)(c) s 26F(3)(d) Rules 5-4
Governing body Giving the governing body the information it needs to oversee your risks, unless your business is an individual. s 26F(4)(a) Rules 5-6
Compliance officer reports The compliance officer reporting to the governing body at least once every 12 months, unless one person holds both roles. Rules 5-7
Roles Designating the compliance officer, and the senior manager or managers who approve the risk assessment and the policies. s 26F(4)(b) s 26F(4)(c)
Staff checks Assessing the skills, knowledge, expertise and integrity of people in AML/CTF roles, before they start and while they work for you. s 26F(4)(d) Rules 5-8
Training Initial and ongoing training suited to each person's function, risks and responsibilities, and readily understandable. s 26F(4)(e) Rules 5-9
Independent evaluation How often your program is independently evaluated (at least once every 3 years) and how you respond to the report. s 26F(4)(f) Rules 5-10
Accurate reports Making sure what you report to AUSTRAC is complete, accurate and free from unauthorised change. Rules 5-11
Possible suspicious matters Reviewing relevant material in time and deciding as soon as practicable whether you have a suspicion to report. Rules 5-12
Tipping off Safeguards so that nobody in the firm tips off a client about a suspicious matter report. Rules 5-13
Real estate settlements For an agent or conveyancer relying on another business under Rules 6-33: how you verify client information before settlement if you do not receive it. Rules 5-20

Proliferation financing. You do not need separate policies for proliferation financing if you reasonably assess that risk as low and your money laundering and terrorism financing policies manage it appropriately. If you rely on this, the burden of showing it is on you, so record your reasons in the risk assessment.7

Approvals your policies must require

Your policies must make sure a senior manager approves the step before you:8

  • start acting for a client if the client, a beneficial owner, or a person the client acts for is a foreign politically exposed person (always);
  • start acting where that person is a domestic or international organisation politically exposed person and the client's risk is high;
  • enter a written agreement to rely on another business's client identification and verification under s 37A.

If an existing client becomes a politically exposed person in those circumstances, a senior manager must decide whether you continue.8 For politically exposed persons you must also establish their source of wealth and source of funds: always for a foreign one, and for a domestic or international organisation one where the risk is high.9

The sanctions policy must refer to the Autonomous Sanctions Act 2011 and the Charter of the United Nations Act 1945, which the Rules name.10 We have not summarised how those Acts work. AUSTRAC points businesses to the lists published by the Department of Foreign Affairs and Trade on its risk assessment page.

Tipping off

It is an offence to disclose that a suspicious matter report has been, or must be, made, where the disclosure would or could reasonably be expected to prejudice an investigation. The penalty is imprisonment for 2 years or 120 penalty units, or both.11 Your policies must set out the safeguards that stop this happening.12

Lawyers and qualified accountants have a narrow exception. They may disclose information about a client's affairs in good faith to dissuade the client from conduct that is, or could be, an offence.11 It is an exception to the offence, not a general permission to discuss a report.

Who does what

  1. Governing body

    Oversees how the firm identifies and assesses its risks and whether it complies with its policies and the law, and takes reasonable steps to make sure it does. If your business is an individual, that individual is the governing body. s 26H s 5

  2. Compliance officer

    Oversees day-to-day compliance and speaks to AUSTRAC for the firm. Must be employed or engaged at management level, with enough authority and resources, a resident of Australia and a fit and proper person. Designate one within 28 days of your first designated service and notify AUSTRAC within 14 days of designating them. s 26J s 26K s 26L s 26M Rules 5-14

  3. Senior manager

    Approves the risk assessment, the policies and every update. The governing body must be told in writing of each update to the risk assessment as soon as practicable. s 26P

In a small practice one person may hold all three roles. Where the compliance officer is the same individual as the governing body, or the business is an individual, the Rules 5-7 reports to the governing body do not apply.13

Write it down before your first client

You must document your risk assessment and your policies before you first provide a designated service to a customer. Each later update must be documented within 14 days.14 You must not start providing a designated service until your policies exist, and once they exist you must follow them.15 AUSTRAC can ask for the documents.16

Independent evaluation

Your program must be independently evaluated at least once every 3 years. The evaluation covers the steps you took in your risk assessment, the design of your policies, whether you follow them, and whether you are managing your risks. The evaluator gives a written report to your governing body and to the senior manager who approves the program.17

For firms whose enrolment was due on 29 July 2026, the first evaluation must happen before a date set by the last two digits of the enrolment identifier.18

First independent evaluation, by enrolment identifier
Last two digits of your enrolment identifier Evaluate before
Both odd (for example 35) 30 June 2029
Odd, then even (for example 36) 31 December 2029
Both even (for example 46) 30 June 2030
Even, then odd (for example 47) 31 December 2030

Because we write program documents, we do not carry out independent evaluations. The set-up service plans the evaluation with you and you choose the evaluator.

The free option: AUSTRAC's starter kits

AUSTRAC publishes free program starter kits for accountants, conveyancers, jewellers, the legal profession and real estate. The release we checked is 1.1, dated 10 June 2026.19 Each kit has suitability criteria. For the accountant and real estate kits they include 15 or fewer personnel, mostly Australian-resident individual clients, no overseas property, no fully remote self-service options and not being part of a large reporting group. For a practice outside the profile, the accountant kit says "you cannot rely on the starter kit to meet AUSTRAC's regulatory expectations of an appropriate AML/CTF program for your practice". AUSTRAC also says its guidance "isn't a substitute for legal advice".20 Check the criteria for your sector on AUSTRAC's program starter kits page before you choose.

AUSTRAC links on this page open in a new window. AUSTRAC has not reviewed or endorsed this guide.

Where we fit

Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.

Sources

Law is quoted from the authorised text on the Federal Register of Legislation, opened 25 September 2026. AUSTRAC pages are guidance, not law.

  1. AML/CTF Act s 26B. legislation.gov.au/C2006A00169/latest/text

  2. AML/CTF Act s 26F(4)(a)–(c).

  3. AML/CTF Act ss 26C(2) and 26F(1)(c).

  4. AML/CTF Amendment Act 2024 (C2024A00110), Schedule 1, item 30, and s 2 (commencement of Schedule 1); Schedule 3, item 11. legislation.gov.au/C2024A00110/latest/text

  5. AML/CTF Act s 26C(1) and (3).

  6. AML/CTF Act s 26F(1).

  7. AML/CTF Act s 26F(11) and (12).

  8. AML/CTF Rules 2025 (F2025L01026), rule 5-5(1) and (1A). legislation.gov.au/F2025L01026/latest/text

  9. AML/CTF Rules 2025, rules 6-23 and 6-24.

  10. AML/CTF Rules 2025, rule 5-3.

  11. AML/CTF Act s 123(1), (2) and (4).

  12. AML/CTF Rules 2025, rule 5-13.

  13. AML/CTF Rules 2025, rule 5-7(3).

  14. AML/CTF Act s 26N; AML/CTF Rules 2025, rule 5-15.

  15. AML/CTF Act ss 26F(8) and 26G.

  16. AML/CTF Act s 26Q.

  17. AML/CTF Act s 26F(4)(f); AML/CTF Rules 2025, rule 5-10.

  18. AML/CTF Transitional Rules 2026 (F2026L00393), s 17. legislation.gov.au/F2026L00393/latest/text

  19. AUSTRAC, "Program starter kits" and "Updates to the accountant program starter kit", read 25 September 2026. Guidance, not law.

  20. AUSTRAC, "Accounting program starter kit: Getting started" and "Real estate program starter kit: Getting started", read 25 September 2026. Guidance, not law. © AUSTRAC for the Commonwealth of Australia 2026, CC BY 4.0.

Questions

Is the old Part A and Part B structure still used?

No. That structure was repealed in March 2026 and never applied to firms regulated from 1 July 2026. Your program is what s 26B says it is: your ML/TF risk assessment plus your AML/CTF policies. Governance, such as the compliance officer and approvals, sits inside the policies (s 26F(4)).

What must the policies cover?

The matters in s 26F(3) and (4): identifying significant changes; customer due diligence under Part 2; reviewing the policies at least once every 3 years and after a risk-assessment review; keeping the governing body informed; designating the compliance officer and the approving senior managers; personnel due diligence; training; and independent evaluations. The Rules add more in Part 5: when you collect or verify client information, including source of wealth and source of funds (5-2); sanctions (5-3); senior-manager approvals (5-5); reporting to the governing body (5-6, 5-7); assessing possible suspicious matters (5-12); and tipping-off safeguards (5-13). The table on this page lists each one.

When must it be documented?

Before you first provide a designated service to a customer. After that, each update to the risk assessment or the policies must be documented within 14 days (s 26N; Rules 5-15).

Who approves it?

A senior manager: someone who makes, or takes part in making, decisions that affect the whole or a substantial part of the business. The senior manager approves the risk assessment, the policies and every update to either (s 26P). If your business is an individual, such as a sole principal, that individual is also the governing body (s 5).

Ready to buy

AML/CTF Program Kit

All four sector editions — accountants, real estate agencies, conveyancers and legal practices — as editable Word documents. No subscription.

Prefer it done for you? The set-up service starts at A$990 and includes the kit.

A$497 one-off, includes GST of A$45.18

Buy the kit — A$497

After payment you go straight to your download page.

Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.