Obligations
AML/CTF personnel due diligence and role-based training
People can prevent, enable or fail to recognise financial crime. Australian AML/CTF personnel controls therefore extend beyond an annual awareness module for employees. A reporting entity must identify roles relevant to its obligations, assess personnel due diligence needs according to role risk, and give those people training suited to their functions and exposure. Relevant personnel can include directors, partners, contractors, consultants, volunteers, interns and people supplied by an outsourced service provider. This guide shows how to build a proportionate framework without collecting unnecessary personal information or treating every role as equally risky. Employment, privacy, discrimination, surveillance and spent-conviction laws still apply, so proposed checks should be reviewed for legal authority and fairness.
Step-by-step process
Map relevant roles
Assess each role's AML authority, access, exposure and capacity to override controls.
Set proportionate checks
Define lawful skills, knowledge, expertise and integrity evidence for each risk tier.
Train for the function
Deliver induction and ongoing scenarios matched to actual professional responsibilities.
Test and improve
Measure competence through assessments and file outcomes, then remediate gaps securely.
Identify roles by access, influence and exposure
Start with roles, not names. AUSTRAC identifies functions involving governance, program operation, customer onboarding, reporting, high-risk approvals, transaction or matter handling, override capability, audit trails, outsourcing and access to sensitive AML information. Include people exposed to ML/TF/PF attempts and those who can weaken, bypass or conceal a control. A receptionist with no onboarding discretion may need awareness training, while a contractor configuring screening rules can require deeper due diligence and specialist training.
Document a role-risk assessment covering decision authority, customer contact, funds or valuable property, system privileges, confidential report information, ability to override, level of supervision and consequence of misconduct or error. Map each relevant role to required checks, training modules, frequency, access restrictions and escalation. Reassess when duties, systems or service lines change; relying on a static human-resources job title can miss the risk created by informal responsibilities.
Make personnel due diligence proportionate
AUSTRAC describes personnel due diligence as a risk-based assessment of skills, knowledge, expertise and integrity. Evidence can include qualifications, experience, knowledge testing, interviews, references and conflict declarations. For higher-risk roles, lawful integrity checks may be considered under documented policy. Police, sanctions, adverse-media, insolvency or financial checks should never be automatic simply because they are available; establish necessity, legal authority, relevance, consent and secure handling.
Complete checks at the appropriate stage before high-risk access or authority is granted, and record the outcome rather than retaining excessive raw data. Define disqualifying or escalated results, who decides, how the person can correct inaccurate information and what controls can mitigate a concern. Reassessment can be periodic for high-risk roles and event driven for changes such as promotion, misconduct allegations, unexplained override behaviour, conflicts, control failures or a significant change in personal responsibilities.
Deliver training that matches the work
Initial training should occur when a person begins a relevant role and before they independently perform higher-risk tasks. Core content includes the firm's risks and program, designated-service boundaries, CDD, beneficial ownership, ongoing monitoring, escalation, SMRs, tipping off, sanctions, record keeping and consequences of non-compliance. Tailor examples to the profession: a conveyancer needs settlement and trust-money scenarios, while a precious-items salesperson needs linked-transaction and payment-pattern examples.
Ongoing training should respond to role changes, policy updates, typologies, incidents, evaluation findings and quality-assurance results. Short scenario exercises, supervised files and decision simulations often reveal competence better than a generic video. Give managers, the compliance officer, governing body and technical administrators content suitable for their distinct responsibilities. Contractors and outsourced teams need training where their work is relevant; a contractual statement that they are trained is not enough without evidence and oversight.
Measure effectiveness, not attendance alone
Keep role mapping, due-diligence outcomes, training content, version, completion, assessment and remediation records. Test whether learning changes decisions through file review, phishing-style simulations where appropriate, alert quality, escalation accuracy, observed practice and interviews. Completion rates can reveal overdue learning but cannot show that people recognise a suspicious pattern or protect confidential SMR information.
Set competency thresholds and a process for failed assessments. Responses may include coaching, supervised work, retraining, restricted access or reassignment, proportionate to risk. Analyse recurring errors by role and control: if many people misunderstand the same process, the policy, system or training may be defective. Report material gaps and overdue high-risk training to the compliance officer and governing body, together with a funded remediation plan.
Operate a privacy-conscious personnel control cycle
Some businesses providing only the item 54 designated service may fall within specific AUSTRAC exemptions from personnel due diligence and training requirements. That setting depends on exact conditions and does not justify reducing controls in a mixed-service business. Even where a legal exemption applies, basic competence, integrity and confidentiality controls may remain necessary under other duties and sound risk management.
- Inventory roles, including non-employees and outsourced personnel, and assign a documented AML risk tier.
- Define lawful, necessary checks for each tier and restrict access to sensitive personnel information.
- Complete and approve due diligence before granting relevant high-risk authority or system access.
- Assign induction and role-specific training, then test understanding with realistic work scenarios.
- Monitor trigger events, control performance, overdue actions and changes in role risk.
- Retain proportionate evidence and securely dispose of personal information when legal and business retention needs end.
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
Frequently asked questions
Does personnel due diligence apply only to employees?
No. AUSTRAC's role guidance extends to people employed or engaged in relevant roles, which can include contractors, consultants, volunteers, interns and service-provider personnel. Assess the function and access rather than payroll status, and allocate responsibility for obtaining and reviewing evidence.
Does every staff member need a police check?
No. Due diligence should be proportionate to role risk and comply with applicable employment, privacy and discrimination law. Document why a particular check is necessary and relevant, obtain required consent, provide a correction process and limit collection and access.
Is annual online training sufficient?
Not automatically. Frequency and content should reflect the role, risk and changes in the business. Initial and ongoing training must be understandable and effective. Use scenarios, assessments, file review and observed performance to confirm capability rather than relying only on attendance.
Who is responsible when training is outsourced?
The reporting entity remains responsible for ensuring relevant personnel receive appropriate and effective training. Review provider content against the business's risks and policies, retain completion and assessment evidence, address failures, and update material when obligations or service patterns change.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.