Obligations

AML/CTF checklist for new Australian reporting entities

Becoming a reporting entity under the AML/CTF Act is a threshold moment for a professional practice: from that point the business must operate an AML/CTF program, not just prepare one. The practical first 90 days look different from the policy debate. This checklist follows the order AUSTRAC's program guidance uses - governance, risk, program, CDD, reporting and records - so a new reporting entity can sequence the work without building compliance backwards. It is a starting structure, not legal advice, and every item should be confirmed against the current Act, Rules and AUSTRAC guidance for the practice's services.

Week 1: enrol and appoint

Enrolment is not the same as compliance. The business is a reporting entity from the moment it provides a designated service, and obligations run from that point even if enrolment is delayed. Late enrolment is still required immediately.

  • Confirm which designated services the practice provides and record the service analysis
  • Enrol with AUSTRAC through AUSTRAC Online if not already enrolled
  • Appoint the AML/CTF compliance officer at management level and notify AUSTRAC
  • Confirm the governing body understands its accountability and the program's scope

Weeks 2-4: assess and document risk

The risk assessment drives everything else. A program copied from a template without a practice-specific risk assessment is a common finding in AUSTRAC enforcement matters. Record why each rating was chosen.

  • Map the customer types, products, delivery channels and geographical exposures
  • Complete the money laundering, terrorism financing and proliferation financing risk assessment
  • Write the AML/CTF program, including CDD, enhanced CDD, reporting and record-keeping policies
  • Use an AUSTRAC starter kit only where the suitability criteria are met, and customise it

Weeks 5-8: stand up CDD and reporting

The controls must exist before the next new client, not after. A reporting entity cannot lawfully provide a designated service without applicable customer identification procedures, so the CDD workflow is the operational gate.

  • Define initial CDD steps for each customer type the practice will meet
  • Configure PEP, sanctions and adverse-media screening for customers and beneficial owners
  • Define ECDD triggers and source-of-funds evidence expectations
  • Set the SMR, TTR and IFTI decision process with deadlines and restricted access
  • Establish the secure client-collection channel and evidence storage

Weeks 9-12: train, test and retain

A new program is only as reliable as its first live files. Test the workflow before it is needed under pressure, and fix anything the test exposes. Keep the test evidence with the program records.

  • Deliver role-based AML/CTF training and record completion
  • Run a controlled test: a new client through scope, CDD, screening and approval
  • Confirm records are retained for the required period with restricted access
  • Set the independent-evaluation and review calendar in the program

Official sources

Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.

Frequently asked questions

What is the first obligation of a new reporting entity?

Enrol with AUSTRAC, appoint a compliance officer and stop providing designated services without applicable customer identification procedures. The obligations attach from the first designated service, not from a later enrolment date.

Can a template program satisfy the requirements?

A template can be a starting point, but the program must reflect the practice's assessed ML/TF/PF risk, services, customers and controls. AUSTRAC starter kits are optional for eligible small practices and must be checked against their suitability criteria.

How quickly must staff be trained?

Training should be delivered before staff perform client-facing duties under the program and refreshed on a risk-based schedule. AUSTRAC expects personnel to understand their role in CDD, reporting and the program.

What records must a new reporting entity keep?

The program, risk assessment, CDD evidence, transaction and reporting records, and training records, for the periods the Act and Rules require - commonly seven years. Retention must be usable, not just stored.

Put it into practice

Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.

This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.