Obligations
AML/CTF compliance officer and governance guide
Effective AML/CTF governance separates three functions even when a small practice assigns them to the same person: governing-body oversight, senior-manager approval and the compliance officer's day-to-day coordination. A title on an organisation chart is not enough. The appointed people need authority, information, resources, competence, escalation routes and evidence that they perform the role. Newly regulated entities also need to manage appointment and AUSTRAC notification timing under the current law and transitional settings. This guide turns those requirements into an operating model suitable for a sole-director practice, partnership or larger group. Exact eligibility, appointment and notification dates should be checked against current AUSTRAC guidance and the entity's commencement and enrolment facts.
Step-by-step process
Assign the functions
Define governing-body, senior-manager, compliance-officer and deputy responsibilities separately.
Assess and appoint
Verify eligibility, fitness, conflicts, authority, competence and resources, then document appointment.
Notify and enable
Meet the applicable AUSTRAC notification date and provide access, budget and escalation powers.
Oversee performance
Report decision-useful information, record challenge and track remediation through governance.
Separate the three governance functions
The governing body oversees whether the business appropriately manages ML/TF/PF risk and complies with the program. A senior manager approves the risk assessment and AML/CTF policies and performs other required decisions. The AML/CTF compliance officer communicates with AUSTRAC, coordinates day-to-day compliance, supports effective operation of policies and reports to the governing body. Document these responsibilities separately so important decisions do not disappear between broad job descriptions.
In a small business, one person may perform more than one function where the legal requirements can be met. The file should still show which hat the person was wearing for each approval, review or escalation. Consider conflicts and self-review: a person who designs and operates every control needs credible challenge from another competent person where possible. Growth, absence or a complex high-risk matter may require deputies, external expertise or additional governing-body attention.
Appoint a fit, empowered compliance officer
AUSTRAC says the officer must be employed or engaged at management level, have sufficient authority, independence, resources and expertise, and be fit and proper. Where services are provided at or through an Australian permanent establishment, the residence requirements in current guidance must also be met. Assess qualifications, experience, integrity, conflicts, capacity and access to senior decision-makers. Reassess suitability periodically and when circumstances change.
The role needs direct access to customer, transaction, matter, screening, reporting and exception information. Give the officer authority to pause a designated service, require enhanced CDD, escalate an SMR decision, commission control testing and obtain resources. Budget, system access and protected time should be explicit. A nominal appointment of someone who cannot see activity or challenge revenue owners is unlikely to deliver effective compliance.
Control appointment, notification and absence
AUSTRAC's standard guidance describes appointment within 28 days of starting to provide designated services and notification to AUSTRAC within 14 days of appointment. Transitional arrangements affected newly regulated entities around 1 July 2026, including a later-of timing described by AUSTRAC. Because the relevant date can depend on enrolment and commencement facts, record the calculation, appointment instrument, acceptance, eligibility assessment and notification confirmation rather than relying on a generic calendar entry.
The business must maintain continuity of the compliance function. Nominate an appropriately capable deputy or documented cover process for leave, vacancy and conflicts. Specify who receives regulator communications, makes urgent customer or reporting decisions and informs the governing body. When the officer changes, repeat eligibility and conflict checks, transfer open issues securely, update AUSTRAC within the applicable time and retain evidence of both cessation and appointment.
Give the governing body decision-useful information
The compliance officer should report to the governing body at least once every 12 months, and material matters should be escalated sooner. A useful report covers changes in risk, customer and service exposure, CDD exceptions, overdue reviews, screening outcomes, monitoring and SMR governance, training, personnel due diligence, record keeping, independent evaluation, breaches, remediation and resource constraints. Protect sensitive reporting information and avoid unnecessary disclosure that could create tipping-off risk.
Governing-body minutes should show challenge and decisions, not merely receipt. Record questions, requested analysis, approved risk appetite, remediation deadlines, resources and follow-up. Senior-manager approvals of the risk assessment and policies should use current versions and list material changes. Dashboards need context: volumes and timeliness are useful, but they should be paired with quality sampling and themes so a high completion percentage does not conceal weak evidence.
Create an auditable governance calendar
A calendar is only a minimum. Event-driven escalation remains essential when a material risk or control issue emerges between meetings. Periodically trace a governance decision to implementation in customer files and systems. That confirms whether oversight changes behaviour rather than producing minutes alone.
- Issue role charters for the governing body, senior manager, compliance officer and deputy, including authority and escalation thresholds.
- Document appointment, fit-and-proper assessment, residence and management-level eligibility, conflicts and AUSTRAC notification evidence.
- Schedule risk and policy approvals, governing-body reporting, control attestations, training, evaluation and remediation reviews.
- Create immediate escalation paths for suspected reporting failures, sanctions concerns, serious control breakdowns and regulator contact.
- Maintain an obligations register showing owner, evidence, frequency, due date, status and governing-body visibility.
- Test absence cover and information access so the compliance function continues when a key person is unavailable.
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
Frequently asked questions
Can the owner of a small practice be the compliance officer?
Potentially, if the person meets the current management-level, residence, fit-and-proper, authority, independence, resource and expertise requirements. The practice should document role separation, manage self-review and conflicts, and arrange competent cover rather than assuming size removes governance duties.
How quickly must an officer be appointed and notified?
AUSTRAC's standard guidance states appointment within 28 days of starting designated services and notification within 14 days of appointment. Transitional timing applied to newly regulated entities in 2026. Calculate the deadline from the entity's actual commencement and enrolment facts using current guidance and retain proof.
How often must the officer report to the governing body?
AUSTRAC states at least once every 12 months, but material risks, breaches, reporting failures or resource problems should be escalated sooner. Set frequency according to risk and ensure reports contain enough evidence for informed oversight and recorded decisions.
Does outsourcing compliance remove management responsibility?
No. External support can add expertise or capacity, but the reporting entity remains responsible for its obligations and internal governance. Confirm who holds the formal role, meets eligibility requirements, accesses information, makes decisions and reports to the governing body.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.