Obligations

The AML/CTF independent evaluation (independent review): who can do it, what it covers and when yours is due

The independent evaluation, often called the independent review or AML audit, is the obligation small firms postpone because it sounds expensive. It need not be. This page explains what the evaluation has to test, who is allowed to do it, how to scope one for a ten-person practice, and exactly when the first one is due under the Transitional Rules 2026.

Updated · Checked against AUSTRAC guidance and the legislation

Seven navy archive box files with teal labels in a row on an office shelf.
In short

An AML/CTF independent evaluation is a review of your program by someone independent of its design and day-to-day operation, done at least once every three years. It tests whether the program meets the Act and the Rules, whether it reflects your actual ML/TF risk and whether the firm follows it. The evaluator does not have to be an external consultant, but cannot be the compliance officer reviewing their own work. For Tranche 2 entities the first evaluation is due between 30 June 2029 and 31 December 2030, on a date set by the last two digits of the AUSTRAC account number.

Key points
  • At least every three years, and sooner after a material change to the program.
  • Independent means not involved in designing or running the program. Internal is allowed in principle; in a small firm it is usually external.
  • It tests three things: compliance with the law, fit with your real risks, and whether staff follow it.
  • First deadline for new entities: 30 June 2029, 31 December 2029, 30 June 2030 or 31 December 2030, by account number.
  • Scope it to your size: half a day of document review and interviews for a ten-person firm.

What the evaluation is for

Your own reviews check whether the program is up to date. The independent evaluation checks whether it works: whether it complies with the Act and the Rules, whether the risk assessment describes your business honestly, whether the policies respond to those risks and whether the people in the firm do what the document says. Its findings go to the governing body (in a small firm, the partners or director) and feed the next revision of the program.

Who counts as independent

Someone with the skills to assess an AML/CTF program who was not involved in designing it or operating it. The Rules do not require an external person: a partner who has nothing to do with compliance could do it in a larger firm. In a firm of one to ten people, in practice that means an external evaluator: an accountant or lawyer with AML/CTF experience, a compliance consultant, or a peer firm under a reciprocal arrangement. The compliance officer cannot evaluate their own program.

What it covers

  • Legal compliance: does the program contain everything the Act and the Rules require?
  • Risk: does the risk assessment match the firm's actual customers, services, channels and jurisdictions? Has anything changed since it was written?
  • Operation: are customers actually identified as the policy says? Are reviews done? Are reports lodged on time? Is training recorded?
  • Governance: approvals, version history, the compliance officer's role and reporting line.
  • Findings and recommendations, with a response from management.

When it is due

At least once every three years. The Transitional Rules 2026 stagger the first evaluation for entities that became reporting entities with the reforms, using the last two digits of the AUSTRAC account number: odd-odd 30 June 2029; odd-even 31 December 2029; even-even 30 June 2030; even-odd 31 December 2030. The calculator above applies the rule. After the first one, the three-year clock runs from the date of each evaluation. A material change to the program, for example adding a new designated service, is a reason to bring the next one forward.

Scoping it for a small firm

Half a day is realistic for a firm of one to ten people: an hour reading the program and the version history, an hour sampling client files against the due diligence policy, an hour of interviews (the compliance officer and one or two staff), and the write-up. Ask the evaluator for a short report with a findings table: requirement, what was found, rating, recommendation. Keep the report with the program; the annual compliance report asks whether an evaluation was done.

What evaluators find most often

  • Risk assessments that were never updated after the firm's services changed.
  • Review intervals in the policy that are not met in the files.
  • Training recorded as a one-off at commencement and never repeated.
  • Beneficial ownership not documented for companies and trusts.
  • No record of senior manager approval for program updates.
Interactive

When is my first independent evaluation due?

New reporting entities get a staggered first deadline. Type the last two digits of your AUSTRAC account number (the AAN on your enrolment confirmation).

Enter at least two digits.
Transitional Rules 2026: first evaluation date by the last two digits of the account number
Second-last digitLast digitDue by
oddodd30 June 2029
oddeven31 December 2029
eveneven30 June 2030
evenodd31 December 2030

From the Anti-Money Laundering and Counter-Terrorism Financing (Transitional) Rules 2026. Check the instrument itself before you rely on a date.

Questions people ask

How often is an AML/CTF independent review required?
At least once every three years, and sooner if the program changes materially. The first one for Tranche 2 entities is due between 30 June 2029 and 31 December 2030.
Can my accountant do the independent evaluation?
Yes, if they have AML/CTF knowledge and were not involved in writing or running your program. Independence is about the role, not about being external.
How much does an independent evaluation cost?
It depends on scope. For a firm of one to ten people, half a day of an experienced evaluator's time is realistic. The sector tools in our group produce the records an evaluator needs, which keeps the time down.
Is it the same as an AML audit?
People use the terms interchangeably. The Act calls it an independent evaluation; it is a review of the program and its operation, not a financial audit.

Read next

Sources

Official pages this page was checked against. The date is when we captured the page; the publisher may have updated it since.

General information about Australian AML/CTF law, not legal advice. The Act, the Rules and AUSTRAC's guidance are the primary sources; check them before you rely on a date or a figure.

AML/CTF independent evaluation: who, when, what · AML/CTF Guide