Start with the risk assessment
The program is risk-based, so the risk assessment comes first. Assess the money laundering, terrorism financing and proliferation financing risks of your practice across four lenses: your customers, your services, your delivery channels (face-to-face vs remote) and the jurisdictions you touch. AUSTRAC has published sector-specific risk insights for accountants, lawyers and real estate — use them as the floor, then write what is true for your practice.
What the program document covers
- Governance: compliance officer, senior approval, review cycle and who can change the program
- The risk assessment and how the program responds to it
- Customer due diligence procedures: how you identify and verify clients and beneficial owners, when enhanced due diligence applies, and how screening is done
- Ongoing due diligence: review cycles by risk rating and trigger events
- Reporting procedures: how suspicious matters are escalated internally, reported to AUSTRAC and protected from tipping off
- Record-keeping: what is kept, where, and for how long (seven years)
- Staff training: induction and refreshers, with records
- How the program itself is reviewed and independently evaluated
Approval and version control
The program must be approved by a senior manager — in a small practice, the principal. Every change should be versioned: what changed, who approved it and when. When AUSTRAC asks to see your program, they are also asking to see that it is alive: approvals, reviews and updates.
Starter kits are optional starting points, not the finish line
AUSTRAC's program starter kits are an optional starting structure for small practices that satisfy every published suitability criterion. Confirm eligibility and customise the material to the practice's actual risks and services. The operational program must still connect CDD files, screening outcomes, training records, approvals and dated decisions. Cassandra AML keeps those records connected to the program document so the controls can be demonstrated in use.
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
Frequently asked questions
Can I copy a program template from the internet?
A template is a starting point only. AUSTRAC expects the program to reflect your practice's actual risks and operations. A generic document that does not match how you work is worse than useless in an examination — it shows the program was never real.
How often must the program be reviewed?
Review and update the program following prescribed triggers and at least every three years. Set independent-evaluation frequency according to the business's size, nature and complexity, with an evaluation at least every three years, subject to the transitional timing for the first evaluation. A practice may choose a more frequent internal review cycle, but should label that as its own control rather than a universal statutory timetable.
Who can approve the AML/CTF program?
A senior manager of the reporting entity — for a small practice, typically the principal or managing partner. The approval should be recorded with the date and the version approved.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.