Obligations
Independent evaluation of an Australian AML/CTF program
An independent evaluation asks whether an AML/CTF program is appropriate, compliant and effective in practice. It is additional to management's routine review, quality assurance and governing-body oversight. AUSTRAC states that evaluation must occur at least every three years, with frequency set in the program according to the nature, size and complexity of the business; transitional rules can affect the first due date for newly regulated entities. Independence and competence matter more than whether the evaluator sits inside or outside the organisation. This guide explains how to define scope, preserve evaluator objectivity, test real files and turn findings into verified remediation. It does not prescribe one universal deadline: calculate the applicable date from the current Rules, transitional settings and the entity's circumstances.
Step-by-step process
Plan the evaluation
Calculate timing, define whole-program scope and document risk-based frequency.
Confirm independence
Assess competence, conflicts, prior responsibility, access and reporting authority.
Test effectiveness
Use walkthroughs, data and representative files to test design, implementation and outcomes.
Remediate and verify
Track owners and dates, then independently test evidence before closing findings.
Set frequency and scope from risk
The program should state how often independent evaluation will occur and why that frequency suits the business. Three years is a maximum interval, not a reason to wait when risk or control change warrants earlier work. New high-risk services, acquisition, major system migration, serious breach, repeated CDD failures, regulator concern or significant growth can justify an additional or accelerated evaluation. Record the decision and governing-body visibility.
Scope the whole program over a cycle: governance, risk assessment, policies, designated-service boundaries, CDD, PEP and sanctions controls, ongoing monitoring, reporting, tipping off, records, personnel controls, outsourcing, data and technology. A targeted review may address an urgent issue, but it should not silently replace the required program-wide evaluation. Map every applicable obligation and material risk to an evaluation procedure before fieldwork begins.
Protect evaluator independence and competence
Select a person with sufficient AML/CTF, sector, testing and analytical expertise. Independence means the evaluator can form and report an objective view without reviewing work for which they were materially responsible or being constrained by revenue owners. An internal evaluator may be suitable if organisational position, prior involvement, reporting line and conflicts permit genuine independence. External status alone does not cure a conflict or lack of skill.
Document qualifications, experience, declarations, previous advisory work, access rights and the person who can approve scope changes. The evaluator should report findings without management editing away disagreement and have access to the governing body where material issues arise. If specialist technology, sanctions, legal or data expertise is needed, add it while maintaining clear responsibility for the final opinion. Preserve limitations and unavailable evidence in the report.
Test design, implementation and effectiveness
Design testing asks whether the program addresses current legal obligations and the risks identified. Implementation testing asks whether policies are embedded in systems, roles and workflows. Effectiveness testing asks whether controls produce reliable outcomes. Use interviews, walkthroughs, data analysis, observation and risk-based file samples across services, customer types, locations and time periods. Include exceptions, declined work, overrides and closed files rather than sampling only clean completions.
Trace end to end. For example, take a complex customer from initial scope and identification through ownership, risk, screening, approvals, service activity, ongoing review and reporting consideration. Reperform selected decisions against evidence and current policy. Test whether monitoring parameters reflect the risk assessment, whether alerts are timely and well resolved, and whether governance receives accurate information. Record sampling rationale and do not generalise beyond what the evidence can support.
Write findings that management can fix
Each finding should state the requirement or control objective, condition observed, evidence, cause, risk and recommended outcome. Grade severity using defined criteria that consider regulatory exposure, customer or transaction impact, duration, population and compensating controls. Separate isolated documentation defects from systemic failures, but do not downgrade missing evidence solely because staff say a step normally occurs.
Management responses should identify an accountable owner, specific action, target date, interim control and residual risk acceptance where necessary. The governing body should see material findings, overdue actions and disputes. Verification must test the completed change on real evidence; closing an action because a policy was rewritten is insufficient if systems, training and files still follow the old process. Preserve the report, response, progress and closure evidence as program records.
Run a credible evaluation lifecycle
AUSTRAC guidance describes specific exemptions for businesses that provide only item 54 where all conditions are met. Mixed-service entities should not rely on that setting. For everyone else, budgeting and evaluator selection should start well before the due date so independence and sample access are not compromised by a rushed engagement.
- Calculate the applicable due date, document risk-based frequency and obtain governing-body visibility of the evaluation plan.
- Confirm evaluator competence, independence, conflicts, reporting rights and access to data and personnel.
- Map obligations and risks to procedures, then select representative and adverse samples.
- Test policy design, operational implementation and real-world effectiveness using reproducible evidence.
- Issue prioritised findings with owners, dates, interim controls and transparent management responses.
- Independently verify remediation and report overdue or ineffective closure to governance.
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
Frequently asked questions
Must the independent evaluator be external?
Not necessarily. The central issues are genuine independence, competence, authority and freedom from material self-review. An internal person can be suitable in some structures, while an external provider can still be conflicted by prior design work. Document the assessment for the chosen evaluator.
Is evaluation required exactly once every three years?
AUSTRAC states at least every three years, with risk-appropriate frequency documented in the program. Material change or failure may justify earlier work, and transitional rules can affect a newly regulated entity's first deadline. Calculate and record the date from current requirements.
Can a compliance checklist count as an independent evaluation?
A checklist alone is unlikely to test implementation and effectiveness. A credible evaluation combines requirement mapping with walkthroughs, evidence, representative samples, reperformance and findings. It should explain scope, method, limitations and the basis for each conclusion.
When is a finding genuinely closed?
Closure requires evidence that the agreed action was implemented and works. Verify revised policy, system configuration, training and affected files as relevant. Record the tester, sample, result and any remaining risk rather than closing solely on management assertion.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.