Map the services before the clients
The service map is the risk assessment's foundation. A practice cannot assess what it has not identified, and an engagement letter that describes everything as 'advisory' does not decide the legal test.
- List every service line and test it against table 6 of the AML/CTF Act
- Separate routine compliance and advice from captured formation, restructuring and transaction work
- Identify item 7 and 8 role services and item 9 address services
- Record the scope decision for each service line and review it when services change
Onboard with entity depth
Accountants commonly meet layered structures, and the file should show the ownership arithmetic: percentages, sources and control roles, not just a conclusion. Cassandra AML's ownership register calculates effective ownership from recorded holdings so the file shows its working.
- Complete initial CDD before providing a designated service
- Map beneficial owners for companies and trusts, including indirect holdings
- Verify the source of funds and wealth where risk requires it
- Screen customers, owners and controllers for PEPs, sanctions and adverse media
- Record the risk rating with reasons
Monitor and report
Accounting firms see both sides of a transaction, which makes their files powerful. The discipline is to connect the client, the entity, the funds and the decision in one record rather than leaving the reporting analysis in an inbox.
- Apply ongoing CDD on risk-based cycles and trigger events
- Review transactions for consistency with the customer's profile
- Lodge SMRs within the deadline and protect SMR-related information
- Report TTRs for physical currency thresholds
- Document every reporting decision, including the decision not to report
Records, training and evaluation
An accounting practice's AML evidence is strongest when it mirrors the audit discipline clients already expect: dated, sourced, approved and retained. Run the AML program the way the firm runs its files.
- Retain the service map, risk assessment, program, CDD and reporting records
- Deliver role-based training and record completion
- Conduct the independent evaluation on the program's calendar
- Test the workflow with a controlled client file
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
Frequently asked questions
Which accounting services are designated?
Entity formation and restructuring, specified transactions including business and real-estate transactions, client-money and property services, and certain nominee, trustee and address services can be designated. Routine tax, BAS and general advice are not on their own.
What is the first step for an accounting firm?
Map every service line against table 6 and record the conclusion. The scope map drives enrolment, risk assessment, CDD and reporting.
Do we need to verify beneficial owners of every entity?
For entity customers receiving designated services, identify and verify the beneficial owners and controllers under the customer-type rules, then screen and monitor them.
What records should the checklist produce?
A service map, risk assessment, program, CDD and verification evidence, source-of-funds records, reporting decisions and training records - retained for the applicable periods.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.