Part one: the risk assessment
An honest description of how your business could be used to launder money, considering your customers (who they are, where they are, whether any are politically exposed), your services, how you deliver them (face to face or remotely) and the jurisdictions involved. The output is a rating of your inherent risk and a list of the factors that drive it.
Part two: the policies
- Customer due diligence: what you collect, how you verify, when you apply enhanced due diligence.
- Ongoing monitoring and periodic reviews by risk level.
- Reporting: how a staff member escalates a concern and how the compliance officer lodges reports within the deadlines.
- Record keeping for seven years.
- Staff training and screening.
- Governance: the compliance officer, senior management approval, and how the program is reviewed and independently evaluated.
Templates: useful, with one warning
A template gets the structure right and saves days. The risk is adopting it unchanged: a program that describes a firm that is not yours is worse than a short one that is. Answer a questionnaire about your own business, generate the document from those answers, read it, change what does not fit, and then adopt it. Each sister site offers a sample program for its sector and a tool that generates one from your answers.
Approval, review and independent evaluation
A senior manager must approve the program and each update to it. It must be kept current: reviewed whenever your services, customers or the law change and at regular intervals; a yearly review is common practice. The Act and the Rules also require an independent evaluation of the program at least once every three years, at a frequency you set and justify in your policies. For a small firm it can be done by a suitably skilled person who is independent of the program's design and operation.
Questions people ask
- Do I still need Part A and Part B?
- No. The reformed regime replaced the Part A/Part B structure with a single program built on a risk assessment and policies. Existing entities had to restructure by 31 March 2026.
- How long should a small firm's program be?
- Long enough to describe your actual risks and procedures, usually ten to fifteen pages. Length is not compliance; accuracy is.
- Who can do the independent evaluation?
- Someone independent of the program's design and operation with the skills to assess it. It does not have to be an external consultant, but it cannot be the compliance officer evaluating their own work.
Sources
Official AUSTRAC guidance this page was checked against. The date is when we captured the page; AUSTRAC may have updated it since.
- Your AML/CTF program (Reform) · AUSTRAC, captured 05 Dec 2025
- Step 2: Identify and assess your risks: risk assessment (Reform) · AUSTRAC, captured 27 Dec 2025
- Step 3: Mitigate and manage your risks - AML/CTF policies (Reform) · AUSTRAC, captured 27 Dec 2025
- Step 4: Review and update your AML/CTF program (Reform) · AUSTRAC, captured 05 Dec 2025
- Step 5: Conduct an independent evaluation (Reform) · AUSTRAC, captured 15 Dec 2025
- Governance and oversight for sole traders and micro businesses (Reform) · AUSTRAC, captured 13 Dec 2025
General information about Australian AML/CTF law, not legal advice. The Act, the Rules and AUSTRAC's guidance are the primary sources.
