Governing body
Exercises ongoing oversight of the organisation’s ML/TF risk assessment and compliance with its AML/CTF policies and obligations.
The Act defines the program; AUSTRAC’s starter kits show how suitable businesses can put it into practice. Here is how risk, policies, people, customer work and review fit together.
The short answer
Under section 26B of the AML/CTF Act, an AML/CTF program comprises the reporting entity’s ML/TF risk assessment and its AML/CTF policies.
“An AML/CTF program of a reporting entity comprises: (a) the reporting entity’s ML/TF risk assessment; and (b) the reporting entity’s AML/CTF policies.”
Compilation No. 62 (C2026C00274)
It identifies and assesses the money-laundering and terrorism-financing risks the organisation may reasonably face when providing its designated services. It is specific to the services and circumstances of the reporting entity.
These are the policies, procedures, systems and controls used to manage those risks and meet the organisation’s obligations. They turn the assessment into instructions and controls that can be used in ordinary work.
The two parts work together: the risk assessment identifies the risks the organisation may reasonably face, and the policies set out how those risks will be managed. When the risk changes materially, the organisation should consider whether the related procedures, systems and controls also need to change.
How the program operates
The program is not a document sequence; it is a loop from risk, to controls, to customer work, to review.
The risks the business may reasonably face, judged against what it actually does.
How those risks will be managed in practice.
Who oversees, approves, coordinates and carries out the work.
The program applied to real work, one designated service at a time.
What changed, whether it still works, and what has to be updated.
Review feeds back into the risk assessment: a material change in risk is what prompts the organisation to revisit its policies, procedures, systems and controls.
Assess the real business
A generic “AML risk” document is not the point. Section 26C asks the reporting entity to assess the risks it may reasonably face in providing its own designated services, having regard to the services, customers, delivery channels, countries and relevant AUSTRAC risk information.
Designated services provided or proposed
Types of customers
Delivery channels
Countries dealt with
Relevant risk information communicated by AUSTRAC, plus any matters specified in the Rules
The assessment is not a one-off description of the business. It needs to remain up to date as services, customers, channels, countries or relevant risk information change. The policies then need to respond to the risks the assessment identifies.
This is also why scope comes first. The organisation cannot sensibly assess the exposure created by a service until it has identified what that service is, how it is delivered and who receives it. The same profession may offer several kinds of work, only some of which are designated services, and each can present a different mix of customer, channel, country and transaction risk.
The operating lifecycle

Identify the services and risks, tailor the assessment and controls to the business, and obtain the required approvals.
Apply the program when onboarding customers, performing CDD, making risk decisions and carrying out designated-service work.
Review changes and effectiveness, update the program where required, and keep the records and evidence of the review.
Maintenance is the change-control part of the program. A new service, delivery channel, customer type, country exposure or relevant AUSTRAC risk update can affect the assessment and the controls built from it. Reviews should leave a record of what was considered, who made the decision, what changed and which version was approved. If no amendment is needed, recording that conclusion and its basis can still show that the program was actively considered rather than left untouched.
Responsibilities
The Act separates ongoing oversight, approval, day-to-day co-ordination and the operational work. Clear responsibility does not mean that every business needs four different people; it means the function and its decisions should be understood.

Exercises ongoing oversight of the organisation’s ML/TF risk assessment and compliance with its AML/CTF policies and obligations.
Approves the ML/TF risk assessment and AML/CTF policies, including updates to them.
Oversees and co-ordinates day-to-day compliance and the effective operation of the organisation’s AML/CTF policies.
Carry out the obligations that apply to their work and receive training appropriate to their functions, risks and responsibilities.
In a sole practice or small business, one person may perform more than one of these functions. The responsibilities still need to be understood and evidenced.
From program to customer
The customer workflow follows the service. The organisation first identifies what it is doing, then applies the controls its program sets for that service, customer and level of risk. The sequence is practical, but the decisions remain with the reporting entity.

Enrolment
Enrolment is one step in becoming operational under the regime; it is not the AML/CTF program itself. Confirm the applicable AUSTRAC enrolment requirements and timing for the business, while separately ensuring the required risk assessment, policies and customer-level controls are in place when the Act requires them.
AUSTRAC enrolment processThe product bridge
Lex-AML is being built around this operating model: configure the organisation and its services, operate the AML/CTF program, onboard customers, run and record CDD, manage reviews, and keep the records, evidence and audit trail connected to each decision.
Lex-AML supports the workflow; your organisation remains responsible for its regulatory and customer decisions.
Common questions
This content is general information only. It is not legal, financial or compliance advice. Organisations should check AUSTRAC guidance, legislation, their own AML/CTF Program and professional advice where needed.
See how Lex-AML connects program operation, customer due diligence, reviews, training evidence and the audit trail behind each decision.