For lawyers

AML/CTF checklist for Australian law firms

A law firm's AML/CTF obligations are matter-level, not firm-level abstractions: each matter must be tested against the designated-services table, each party who needs checking must be identified, and trust money must be handled within the statutory boundaries. This checklist gives Australian law firms a sequence that starts with the service, runs through CDD and reporting, and preserves privilege and confidentiality along the way. It is general compliance information, not legal advice, and each item should be confirmed against the current Act, Rules and AUSTRAC guidance.

See the lawyers AML/CTF workspace

Scope each matter

The designated-services analysis is documented, not assumed. AUSTRAC's guidance describes captured legal work, including drafting or reviewing documents that actively advances a captured transaction, while general legal advice and routine document preparation are not designated on their own. Record the reasoning on the file.

  • Test the matter against the professional designated services in table 6
  • Identify the designated service and when it starts
  • Record the boundary for general legal advice and routine drafting
  • Check whether the practice's risk assessment covers the practice area

Identify the parties and complete CDD

In a conveyancing or transaction matter, the parties may include a vendor, purchaser, guarantor, funder or trustee. The program should define which parties receive CDD and at what depth, then apply it consistently. A matter file that shows the party list and the verification is the core of the AML record.

  • Identify the client and the persons on whose behalf the service is received
  • Identify and verify counterparties where the service requires it
  • For entities, map beneficial owners and controllers
  • Screen for PEPs, sanctions and adverse media
  • Complete initial CDD before providing the designated service

Trust money and reporting

Trust money is where laundering risk is highest in legal work, and the reporting obligations attach to the firm's own suspicion, not the client's explanation. The firm should also maintain the privilege analysis separately from the reporting decision, since the two regimes interact.

  • Test client-money and property services against item 3 and its boundaries
  • Keep trust money separate, authorised and reconciled
  • Lodge SMRs within the deadline and protect SMR-related information
  • Report TTRs for physical currency thresholds
  • Preserve legal professional privilege boundaries

Monitor, retain and train

The strongest law firm AML file reads like a well-run matter: parties, evidence, decisions and dates connected in one place. Build the checklist into the matter workflow so compliance is not a separate exercise.

  • Set review triggers for matters and relationships
  • Retain scope, CDD, transaction and reporting records for the required period
  • Deliver role-based training and record completion
  • Test the workflow with a controlled matter

Official sources

Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.

Frequently asked questions

Which legal services are designated services?

The service test matters, not the practice area. Captured work can include drafting or reviewing documents that actively advances a captured transaction, entity or trust formation, specified client-property transactions and certain role or address services.

Do we verify every party in every matter?

No. The program should define which parties receive CDD and at what depth based on the service and risk. The definitions must be applied consistently and the decisions recorded.

How does privilege interact with AUSTRAC requests?

Legal professional privilege and the AML/CTF regime operate separately. A firm should preserve the privilege analysis and meet its reporting obligations within the applicable rules, taking advice where the interaction is complex.

What is the most common gap in law firm files?

A CDD file that verifies the client but not the parties the matter actually requires, or a trust-money record without the transaction context. The matter file should connect both.

Put it into practice

Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.

This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.