Obligations
Writing your AML/CTF program: what AUSTRAC expects in the document
Your AML/CTF program is the document that turns the law into how your practice actually operates. AUSTRAC does not want a shelf-ware policy: the program must reflect your real risks, be approved at senior level, be followed, and be kept current. Here is what goes in it.
Start with the risk assessment
The program is risk-based, so the risk assessment comes first. Assess the money laundering, terrorism financing and proliferation financing risks of your practice across four lenses: your customers, your services, your delivery channels (face-to-face vs remote) and the jurisdictions you touch. AUSTRAC has published sector-specific risk insights for accountants, lawyers and real estate — use them as the floor, then write what is true for your practice.
What the program document covers
- Governance: compliance officer, senior approval, review cycle and who can change the program
- The risk assessment and how the program responds to it
- Customer due diligence procedures: how you identify and verify clients and beneficial owners, when enhanced due diligence applies, and how screening is done
- Ongoing due diligence: review cycles by risk rating and trigger events
- Reporting procedures: how suspicious matters are escalated internally, reported to AUSTRAC and protected from tipping off
- Record-keeping: what is kept, where, and for how long (seven years)
- Staff training: induction and refreshers, with records
- How the program itself is reviewed and independently evaluated
Approval and version control
The program must be approved by a senior manager — in a small practice, the principal. Every change should be versioned: what changed, who approved it and when. When AUSTRAC asks to see your program, they are also asking to see that it is alive: approvals, reviews and updates.
Starter kits are the baseline, not the finish line
AUSTRAC's program starter kits give small practices a legitimate starting structure. The gap between the kit and a working program is everything operational: the CDD files on real clients, the screening outcomes, the training records and the dated decisions. Software like Cassandra AML keeps those operational records connected to the program document so the program is demonstrably in use.
Frequently asked questions
Can I copy a program template from the internet?
A template is a starting point only. AUSTRAC expects the program to reflect your practice's actual risks and operations. A generic document that does not match how you work is worse than useless in an examination — it shows the program was never real.
How often must the program be reviewed?
The program must be kept current and reviewed regularly, and the amended rules introduce independent evaluation expectations. A practical cadence for a small practice is at least annually, plus whenever your services, client base or risk profile changes materially.
Who can approve the AML/CTF program?
A senior manager of the reporting entity — for a small practice, typically the principal or managing partner. The approval should be recorded with the date and the version approved.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser.