Skip to content
AML/CTF program

What an AML/CTF program is — and how to run it

The Act defines the program; AUSTRAC’s starter kits show how suitable businesses can put it into practice. Here is how risk, policies, people, customer work and review fit together.

The short answer

Two things make up the program

Under section 26B of the AML/CTF Act, an AML/CTF program comprises the reporting entity’s ML/TF risk assessment and its AML/CTF policies.

AML/CTF Act 2006 (Cth) — s 26B
“An AML/CTF program of a reporting entity comprises: (a) the reporting entity’s ML/TF risk assessment; and (b) the reporting entity’s AML/CTF policies.”

Compilation No. 62 (C2026C00274)

The ML/TF risk assessment

It identifies and assesses the money-laundering and terrorism-financing risks the organisation may reasonably face when providing its designated services. It is specific to the services and circumstances of the reporting entity.

The AML/CTF policies

These are the policies, procedures, systems and controls used to manage those risks and meet the organisation’s obligations. They turn the assessment into instructions and controls that can be used in ordinary work.

The two parts work together: the risk assessment identifies the risks the organisation may reasonably face, and the policies set out how those risks will be managed. When the risk changes materially, the organisation should consider whether the related procedures, systems and controls also need to change.

How the program operates

The program is not a document sequence; it is a loop from risk, to controls, to customer work, to review.

  1. 01Assess

    ML/TF risk assessment

    The risks the business may reasonably face, judged against what it actually does.

    • designated services
    • customers
    • delivery channels
    • countries
    • AUSTRAC and other relevant risk information
  2. 02Control

    AML/CTF policies

    How those risks will be managed in practice.

    • policies
    • procedures
    • systems
    • controls
  3. 03Assign

    People and responsibilities

    Who oversees, approves, coordinates and carries out the work.

    • governing body oversight
    • senior-manager approval
    • AML/CTF compliance officer
    • relevant personnel and training
  4. 04Operate

    Customer and service workflow

    The program applied to real work, one designated service at a time.

    1. designated service
    2. customer
    3. CDD
    4. risk / decision
    5. records & evidence
  5. 05Review

    Maintain and review

    What changed, whether it still works, and what has to be updated.

    • monitor changes
    • review effectiveness
    • update where needed

Review feeds back into the risk assessment: a material change in risk is what prompts the organisation to revisit its policies, procedures, systems and controls.

The AML/CTF program as an operating loop, not a document sequence

Assess the real business

Your risk assessment starts with the business you actually run

A generic “AML risk” document is not the point. Section 26C asks the reporting entity to assess the risks it may reasonably face in providing its own designated services, having regard to the services, customers, delivery channels, countries and relevant AUSTRAC risk information.

  1. 01

    Designated services provided or proposed

  2. 02

    Types of customers

  3. 03

    Delivery channels

  4. 04

    Countries dealt with

  5. 05

    Relevant risk information communicated by AUSTRAC, plus any matters specified in the Rules

The assessment is not a one-off description of the business. It needs to remain up to date as services, customers, channels, countries or relevant risk information change. The policies then need to respond to the risks the assessment identifies.

This is also why scope comes first. The organisation cannot sensibly assess the exposure created by a service until it has identified what that service is, how it is delivered and who receives it. The same profession may offer several kinds of work, only some of which are designated services, and each can present a different mix of customer, channel, country and transaction risk.

The operating lifecycle

A program is not finished when the documents are written

Illustration: a professional standing inside a circle of two arrows, the upper arrow picked out in gold
Customise, use, maintain — and round again
  1. 01

    Customise and approve

    Identify the services and risks, tailor the assessment and controls to the business, and obtain the required approvals.

  2. 02

    Use the program

    Apply the program when onboarding customers, performing CDD, making risk decisions and carrying out designated-service work.

  3. 03

    Maintain and review

    Review changes and effectiveness, update the program where required, and keep the records and evidence of the review.

See what is inside AUSTRAC’s five program starter kits

Maintenance is the change-control part of the program. A new service, delivery channel, customer type, country exposure or relevant AUSTRAC risk update can affect the assessment and the controls built from it. Reviews should leave a record of what was considered, who made the decision, what changed and which version was approved. If no amendment is needed, recording that conclusion and its basis can still show that the program was actively considered rather than left untouched.

Responsibilities

Who does what

The Act separates ongoing oversight, approval, day-to-day co-ordination and the operational work. Clear responsibility does not mean that every business needs four different people; it means the function and its decisions should be understood.

Illustration: four professionals seated above four documents, one of the documents picked out in gold
Four responsibilities — not necessarily four people

Governing body

Exercises ongoing oversight of the organisation’s ML/TF risk assessment and compliance with its AML/CTF policies and obligations.

Senior manager

Approves the ML/TF risk assessment and AML/CTF policies, including updates to them.

AML/CTF compliance officer

Oversees and co-ordinates day-to-day compliance and the effective operation of the organisation’s AML/CTF policies.

Relevant personnel

Carry out the obligations that apply to their work and receive training appropriate to their functions, risks and responsibilities.

In a sole practice or small business, one person may perform more than one of these functions. The responsibilities still need to be understood and evidenced.

From program to customer

The program becomes real when you provide a designated service

The customer workflow follows the service. The organisation first identifies what it is doing, then applies the controls its program sets for that service, customer and level of risk. The sequence is practical, but the decisions remain with the reporting entity.

  1. 01Identify the service being provided.
  2. 02Confirm whether it is a designated service.
  3. 03Apply the customer-onboarding and CDD rules in the organisation’s program.
  4. 04Establish and verify the required customer information before the designated service where the Act requires initial CDD.
  5. 05Record the customer risk and any escalation or enhanced measures.
  6. 06Continue ongoing CDD and monitoring as required by the program.
  7. 07Keep the records that demonstrate what was done and why.
Illustration: a professional drawing one gold file from a wall of filing-cabinet drawers while three colleagues look on
The end of the workflow is a record someone can find again

Enrolment

Enrolment and the program are separate steps

Enrolment is one step in becoming operational under the regime; it is not the AML/CTF program itself. Confirm the applicable AUSTRAC enrolment requirements and timing for the business, while separately ensuring the required risk assessment, policies and customer-level controls are in place when the Act requires them.

AUSTRAC enrolment process

The product bridge

Where Lex-AML fits

Lex-AML is being built around this operating model: configure the organisation and its services, operate the AML/CTF program, onboard customers, run and record CDD, manage reviews, and keep the records, evidence and audit trail connected to each decision.

Lex-AML supports the workflow; your organisation remains responsible for its regulatory and customer decisions.

Common questions

AML/CTF program FAQ

What is an AML/CTF program?
Under section 26B of the Act, it comprises the reporting entity’s ML/TF risk assessment and AML/CTF policies.
Do I have to use an AUSTRAC starter kit?
No. The obligation is to have an appropriate AML/CTF program. AUSTRAC’s starter kits are practical guidance for reporting entities that meet their stated suitability criteria.
When does the program have to be ready?
The Act contains obligations requiring an up-to-date ML/TF risk assessment before commencing relevant designated services, and the reporting entity must develop and maintain the AML/CTF policies required by Part 1A. The exact application should be checked against the Act, Rules and the entity’s circumstances.
Is AML/CTF training part of the program?
Yes. Section 26F requires AML/CTF policies to deal with training people performing functions relevant to the reporting entity’s AML/CTF obligations, and the Rules specify requirements for that training.

This content is general information only. It is not legal, financial or compliance advice. Organisations should check AUSTRAC guidance, legislation, their own AML/CTF Program and professional advice where needed.

See the workflow in a demo

See how Lex-AML connects program operation, customer due diligence, reviews, training evidence and the audit trail behind each decision.

See the workflow in a demo