Skip to main content
CCassandra AML
Scope checkGuidesPricingSecurityAboutSign inStart free
Menu
Scope checkGuidesPricingSecurityAboutSign inStart free
Guides/Core obligations

Obligations

Independent evaluation of an Australian AML/CTF program

6 min read · Updated 1 August 2026

An independent evaluation asks whether an AML/CTF program is appropriate, compliant and effective in practice. It is additional to management's routine review, quality assurance and governing-body oversight. AUSTRAC states that evaluation must occur at least every three years, with frequency set in the program according to the nature, size and complexity of the business; transitional rules can affect the first due date for newly regulated entities. Independence and competence matter more than whether the evaluator sits inside or outside the organisation. This guide explains how to define scope, preserve evaluator objectivity, test real files and turn findings into verified remediation. It does not prescribe one universal deadline: calculate the applicable date from the current Rules, transitional settings and the entity's circumstances.

On this page

  1. Step-by-step process
  2. Set frequency and scope from risk
  3. Protect evaluator independence and competence
  4. Test design, implementation and effectiveness
  5. Write findings that management can fix
  6. Run a credible evaluation lifecycle
  7. Official sources
  8. Frequently asked questions

Step-by-step process

  1. Plan the evaluation

    Calculate timing, define whole-program scope and document risk-based frequency.

  2. Confirm independence

    Assess competence, conflicts, prior responsibility, access and reporting authority.

  3. Test effectiveness

    Use walkthroughs, data and representative files to test design, implementation and outcomes.

  4. Remediate and verify

    Track owners and dates, then independently test evidence before closing findings.

Set frequency and scope from risk

The program should state how often independent evaluation will occur and why that frequency suits the business. Three years is a maximum interval, not a reason to wait when risk or control change warrants earlier work. New high-risk services, acquisition, major system migration, serious breach, repeated CDD failures, regulator concern or significant growth can justify an additional or accelerated evaluation. Record the decision and governing-body visibility.

Scope the whole program over a cycle: governance, risk assessment, policies, designated-service boundaries, CDD, PEP and sanctions controls, ongoing monitoring, reporting, tipping off, records, personnel controls, outsourcing, data and technology. A targeted review may address an urgent issue, but it should not silently replace the required program-wide evaluation. Map every applicable obligation and material risk to an evaluation procedure before fieldwork begins.

Protect evaluator independence and competence

Select a person with sufficient AML/CTF, sector, testing and analytical expertise. Independence means the evaluator can form and report an objective view without reviewing work for which they were materially responsible or being constrained by revenue owners. An internal evaluator may be suitable if organisational position, prior involvement, reporting line and conflicts permit genuine independence. External status alone does not cure a conflict or lack of skill.

Document qualifications, experience, declarations, previous advisory work, access rights and the person who can approve scope changes. The evaluator should report findings without management editing away disagreement and have access to the governing body where material issues arise. If specialist technology, sanctions, legal or data expertise is needed, add it while maintaining clear responsibility for the final opinion. Preserve limitations and unavailable evidence in the report.

Test design, implementation and effectiveness

Design testing asks whether the program addresses current legal obligations and the risks identified. Implementation testing asks whether policies are embedded in systems, roles and workflows. Effectiveness testing asks whether controls produce reliable outcomes. Use interviews, walkthroughs, data analysis, observation and risk-based file samples across services, customer types, locations and time periods. Include exceptions, declined work, overrides and closed files rather than sampling only clean completions.

Trace end to end. For example, take a complex customer from initial scope and identification through ownership, risk, screening, approvals, service activity, ongoing review and reporting consideration. Reperform selected decisions against evidence and current policy. Test whether monitoring parameters reflect the risk assessment, whether alerts are timely and well resolved, and whether governance receives accurate information. Record sampling rationale and do not generalise beyond what the evidence can support.

Write findings that management can fix

Each finding should state the requirement or control objective, condition observed, evidence, cause, risk and recommended outcome. Grade severity using defined criteria that consider regulatory exposure, customer or transaction impact, duration, population and compensating controls. Separate isolated documentation defects from systemic failures, but do not downgrade missing evidence solely because staff say a step normally occurs.

Management responses should identify an accountable owner, specific action, target date, interim control and residual risk acceptance where necessary. The governing body should see material findings, overdue actions and disputes. Verification must test the completed change on real evidence; closing an action because a policy was rewritten is insufficient if systems, training and files still follow the old process. Preserve the report, response, progress and closure evidence as program records.

Run a credible evaluation lifecycle

AUSTRAC guidance describes specific exemptions for businesses that provide only item 54 where all conditions are met. Mixed-service entities should not rely on that setting. For everyone else, budgeting and evaluator selection should start well before the due date so independence and sample access are not compromised by a rushed engagement.

  • Calculate the applicable due date, document risk-based frequency and obtain governing-body visibility of the evaluation plan.
  • Confirm evaluator competence, independence, conflicts, reporting rights and access to data and personnel.
  • Map obligations and risks to procedures, then select representative and adverse samples.
  • Test policy design, operational implementation and real-world effectiveness using reproducible evidence.
  • Issue prioritised findings with owners, dates, interim controls and transparent management responses.
  • Independently verify remediation and report overdue or ineffective closure to governance.

Official sources

Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.

  • AUSTRAC - Conduct an independent evaluation
  • AUSTRAC - AML/CTF Transitional Rules 2026
  • Federal Register - AML/CTF Rules 2025
  • Federal Register - AML/CTF Act 2006

Frequently asked questions

Must the independent evaluator be external?

Not necessarily. The central issues are genuine independence, competence, authority and freedom from material self-review. An internal person can be suitable in some structures, while an external provider can still be conflicted by prior design work. Document the assessment for the chosen evaluator.

Is evaluation required exactly once every three years?

AUSTRAC states at least every three years, with risk-appropriate frequency documented in the program. Material change or failure may justify earlier work, and transitional rules can affect a newly regulated entity's first deadline. Calculate and record the date from current requirements.

Can a compliance checklist count as an independent evaluation?

A checklist alone is unlikely to test implementation and effectiveness. A credible evaluation combines requirement mapping with walkthroughs, evidence, representative samples, reperformance and findings. It should explain scope, method, limitations and the basis for each conclusion.

When is a finding genuinely closed?

Closure requires evidence that the agreed action was implemented and works. Verify revised policy, system configuration, training and affected files as relevant. Record the tester, sample, result and any remaining risk rather than closing solely on management assertion.

Put it into practice

Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.

Run the free scope checkCreate a free workspace

Keep reading

Obligations

Your AML/CTF program

Read
Obligations

ML/TF/PF risk assessment

Read
Obligations

Officer and governance

Read

This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.

CCassandra AML

AML/CTF compliance workspace for Australian tax agents, accountants, lawyers, conveyancers, real estate professionals, trust and company service providers, and precious-metals and stones dealers — with designated-service decisions and review-ready records.

Owned and operated by Cassandra Research Pty Ltd, an Australian company based in Melbourne, Victoria.

Product

Create workspaceFree scope checkSign inPricingSecurity

AML/CTF guides

All guidesTranche 2 foundationsCore obligationsTax agentsBAS agentsAccountantsLawyersConveyancersReal estateTrust & company servicesPrecious-items dealersKnowledge RSS feed

Company

AboutContactEditorial standards

Legal

Privacy PolicyTerms of ServiceCookie NoticeAccessibility

Cassandra AML assists compliance work. It does not provide legal advice, guarantee compliance or imply AUSTRAC endorsement.

© 2026 Cassandra Research Pty Ltd, Melbourne, Australia. All rights reserved.