An AML/CTF program template under the 2026 rules has two parts: an ML/TF risk assessment of your business (customers, services, delivery channels, jurisdictions, with an inherent risk rating) and the AML/CTF policies that manage that risk (customer due diligence, ongoing monitoring, reporting, record keeping, training and screening, governance). It must be approved by a senior manager, reviewed when things change and independently evaluated at least every three years. A template is only compliant once its answers describe your firm.
- Two parts: risk assessment first, policies second. The policies must respond to the risks you identified.
- Nine sections cover everything AUSTRAC asks for; a ten-person firm's program is usually 10 to 15 pages.
- Three template failures: generic risk assessment, policies the firm does not actually follow, no approval or review record.
- AUSTRAC publishes free starter kits by sector; the sector sites generate a program from a questionnaire.
What a template is for
A template gives you the headings, the order and the regulatory language, so you do not have to work out from the Act what a program must contain. What it cannot give you is the content: your clients, your services, your risks and the procedures you actually follow. AUSTRAC's assessors read programs against the business in front of them. A program that describes a generic firm is the most common failure they report.
Section 1: the business
Example: "Smith & Co is a two-partner accounting practice in Parramatta with four staff. We provide bookkeeping, tax and BAS services, which are not designated services, and the following designated services: setting up and acting as registered office for client companies, and assisting clients to buy and sell businesses. We meet most clients in person; around 20% are onboarded remotely. Our clients are Australian residents and Australian companies."
Section 2: the ML/TF risk assessment
Rate four areas and say why. Customers: who they are, whether any are politically exposed, how many you never meet. Services: which of your designated services could be used to move or hide money (company formation and nominee roles rate higher than most). Delivery channels: remote onboarding and third-party introductions rate higher. Jurisdictions: any link to higher-risk countries. Finish with an overall inherent risk rating and the list of factors behind it. Example: "Inherent risk: medium. Drivers: company formation services; 20% remote onboarding; no high-risk jurisdictions."
Section 3: customer due diligence policy
What you collect for each customer type (individual, company, trust, partnership), how you verify it (documents sighted, electronic verification), how you identify beneficial owners, when you apply enhanced due diligence (high risk, PEPs, SMRs) and when verification may be delayed under the Rules. Say who does it and where the evidence is filed.
Section 4: ongoing monitoring and reviews
How you compare what a client does with the purpose they stated, how often you review files by risk rating (for example 6, 12 and 24 months for high, medium and low), and what triggers an out-of-cycle review.
Section 5: reporting
How a staff member raises a concern, how the compliance officer decides whether a suspicion has formed, how SMRs and TTRs are lodged within the deadlines, and the tipping-off rule. Include the annual compliance report.
Section 6: record keeping
What is kept (identification, verification evidence, risk ratings, reports, training records, each version of the program), where, for seven years, and who can access it.
Section 7: training and personnel
Who is trained, on what, how often, how it is recorded; and the screening you do before someone takes a role that touches designated services.
Section 8: governance
The compliance officer's name and role, the senior manager who approves the program, the governing body's oversight, the review schedule and the independent evaluation plan. For a sole practitioner, the same person can hold the roles; AUSTRAC's guidance on sole traders explains how to document that.
Section 9: approval and version history
A table of versions: date, what changed, who approved. The first entry is the adoption. This table is the first thing an assessor looks for and the thing templates most often leave empty.
Where templates fail
- A risk assessment copied from another firm, with risks you do not have and none of the ones you do.
- Policies that describe procedures nobody in the firm follows. An assessor will ask a staff member how they verify a client and compare the answer with the document.
- No evidence of approval, review or training. A program without a version history reads as a program nobody has opened since it was downloaded.
Free starter kits and generated programs
AUSTRAC publishes a program starter kit for each Tranche 2 sector, with a document library and worked examples. They are the right starting point if you want to write the program yourself. The sector sites in our group (LedgerAML, RealtyAML, PracticeAML) take the other route: a questionnaire about your firm generates the document, each save becomes a new approved version, and reviews and training are logged in the same place.
How to build an AML/CTF program from a template
- 1Describe your business
List the designated services you provide, who your clients are, how you meet them (in person or remotely) and which countries are involved.
- 2Assess the ML/TF risk
For customers, services, channels and jurisdictions, say how each could be used to launder money and rate the inherent risk low, medium or high, with reasons.
- 3Write the policies that answer the risks
Customer due diligence, ongoing monitoring and reviews, reporting, record keeping, training and screening, governance. Each policy should say who does what and when.
- 4Set the governance
Name the compliance officer, the senior manager who approves the program, how often it is reviewed and how the independent evaluation will be done.
- 5Adopt it
The senior manager approves the document and the date is recorded. Keep each version.
- 6Keep it alive
Review when services, clients or the law change, and at least yearly in practice. Record each review and each training session.
Questions people ask
- Is there a free AML/CTF program template?
- AUSTRAC's program starter kits are free and sector-specific. They give you the structure; you still have to write the risk assessment and policies for your own firm.
- How long should an AML/CTF program be?
- For a firm of one to ten people, usually ten to fifteen pages. Length is not what is assessed; whether it describes your business and whether you follow it is.
- Who has to approve the program?
- A senior manager. In a small firm that is a partner, director or the principal. Each update needs approval too, and the dates should be recorded.
- How often must the program be reviewed?
- Whenever your services, clients or the law change, and periodically. Most small firms review yearly and record it. An independent evaluation is required at least every three years.
- Can I use the same program for two businesses?
- Only if they are part of the same reporting group and the program covers both. Otherwise each reporting entity needs a program that describes its own risks.
Read next
Sources
Official pages this page was checked against. The date is when we captured the page; the publisher may have updated it since.
- Develop your AML/CTF program · AUSTRAC, captured 07 June 2026
- Your AML/CTF program overview · AUSTRAC, captured 12 Apr 2026
- Step 2: Identify and assess your risks · AUSTRAC, captured 07 June 2026
- Step 3: Manage and mitigate your risks – AML/CTF policies · AUSTRAC, captured 07 June 2026
- Step 4: Review and update your AML/CTF program · AUSTRAC, captured 12 Apr 2026
- Program starter kits · AUSTRAC, captured 01 July 2026
- Governance and oversight for sole traders and micro businesses · AUSTRAC, captured 17 May 2026
General information about Australian AML/CTF law, not legal advice. The Act, the Rules and AUSTRAC's guidance are the primary sources; check them before you rely on a date or a figure.
