What Is an AML Compliance Program? The Components AUSTRAC Actually Requires

Professional header image for list-based article: What Is an AML Compliance Program? The Components AUSTRAC...

Most Australian businesses subject to financial crime obligations know they need an AML/CTF program. Far fewer know exactly what that program must contain to satisfy AUSTRAC's requirements. The gap between vague awareness and documented compliance is precisely where regulatory risk lives.

The AML/CTF rules in Australia are not suggestions. They prescribe specific, documented components that every reporting entity must have in place, from a formal ML/TF risk assessment to a designated compliance officer, tiered customer due diligence procedures, and structured record-keeping obligations. Getting these right is not a matter of interpretation; it is a matter of building each element deliberately and completely.

This post maps out all 12 mandatory components AUSTRAC requires in a compliant program. It covers who must have one, what each component demands in practice, and what the incoming Tranche 2 reforms mean for newly regulated sectors including real estate agents, lawyers, accountants, and precious metals dealers. Whether you are building a program from scratch or auditing an existing one, this is the concrete, component-by-component breakdown you need to get it right.

What Is an AML/CTF Compliance Program Under Australian Law?

An AML/CTF program is a formal, documented framework that every reporting entity must maintain under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 and the AML/CTF Rules Instrument 2007 (No. 1). It is a legal obligation, not a best-practice aspiration. Any entity providing a designated service must have one in place, and AUSTRAC enforces compliance through audits, enforceable undertakings, and civil penalties.

Programs must be risk-based, reflecting the specific money laundering and terrorism financing (ML/TF) risks your business actually faces based on your customer types, products, delivery channels, and geographic exposure. A copied template that ignores your circumstances will not satisfy AUSTRAC's requirements.

AUSTRAC identifies 12 mandatory components that every compliant program must address. This piece works through each one with enough specificity to support actual program design, not just theoretical awareness.

Timing matters. Tranche 2 reforms open for enrolment on 31 March 2026, bringing real estate agents, lawyers, accountants, precious metals dealers, and virtual asset service providers into scope for the first time. If your business falls into one of these sectors, setting up your AML/CTF program before the enrolment deadline is the essential first step.

Who Needs an AML/CTF Program in Australia?

Any business providing a designated service under the AML/CTF Act must enrol with AUSTRAC and maintain a compliant program. Current regulated entities include financial institutions, remittance providers, digital currency exchanges, and bullion dealers. The Tranche 2 sectors and their 31 March 2026 enrolment date are addressed in detail in the dedicated section below.

Compliance obligations apply regardless of business size. The same 12-component framework applies whether your business is a small practice or a major institution. What scales with size is depth and sophistication; a smaller business with lower-risk customers can implement proportionate controls, but cannot omit components entirely.

Businesses serving higher-risk customers, operating across multiple jurisdictions, or processing significant cash volumes face elevated regulatory scrutiny and must demonstrate correspondingly robust program design.

The essential first step is confirming whether your business is in scope at all. AUSTRAC's designated services table is the authoritative reference. Misidentifying scope is not a technicality; it is an independent compliance risk that AUSTRAC can and does act on.

The 12 Mandatory Components Every AUSTRAC Program Must Include

Once you've confirmed your business is in scope, the next question is concrete: what must your program actually contain?

AUSTRAC's guidance for reporting entities confirms 12 mandatory components, each derived directly from the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 and the AML/CTF Rules Instrument 2007 (No. 1). Every component must be documented in writing, verbal commitments carry no legal weight.

The 12 components fall across four functional domains:

  • Governance and oversight: program adoption, the AML/CTF Compliance Officer, and independent review

  • Customer due diligence: KYC procedures, ongoing monitoring, and employee due diligence

  • Transaction monitoring and reporting: suspicious matter reports, threshold transaction reports, and AUSTRAC feedback procedures

  • Program maintenance: ML/TF risk assessment, record keeping, and enrolment maintenance

Treat this as a checklist, not a compliance aspiration. Each section below identifies what the component requires, what written evidence looks like, and where programs typically break down.

Component 1: ML/TF Risk Assessment

Component 1: ML/TF Risk Assessment

The ML/TF Risk Assessment sits underneath every other component in your program. AUSTRAC requires it to identify and document the specific ML/TF risks your business faces across four dimensions: customer types, designated services, delivery channels, and geographic exposure.

It must reflect your actual business, not a generic template. A remittance provider sending funds to high-risk corridors carries materially different documented risks than a domestic-only payments business. A copied industry template will not withstand AUSTRAC scrutiny.

It is a living document. Any change to your services, customer base, or operating environment triggers a review obligation.

Individual customer risk must feed upward. Documented client risk assessments, using service-specific risk factors, should aggregate into your entity-level ML/TF Risk Assessment, creating an auditable link between micro-level customer risk and your overall risk profile.

It directly drives your due diligence framework. Without a documented risk assessment, you have no defensible basis for assigning customers to Simplified, Standard, or Enhanced Due Diligence tiers. The tiered KYC structure depends entirely on what your risk assessment concludes.

Use a structured tool to assess your AML/CTF risk exposure and keep the documentation audit-ready as your business evolves.

Component 2: ML/TF Risk Awareness Training

Once your risk assessment maps the threats your business faces, training ensures your staff can actually recognise them.

All employees who deal with customers or handle transactions must receive documented AML/CTF training suited to their role. This is a binding obligation under the AML/CTF Rules, not a recommendation.

Training must cover three specific areas:

  • Identifying suspicious behaviour relevant to your business type and customer base

  • Suspicious Matter Reports (SMRs): what triggers one and how the internal escalation process works

  • The tipping-off prohibition under the AML/CTF Act, which prohibits disclosing to a customer or any third party that an SMR has been or may be filed

Training records are your evidence of compliance during an AUSTRAC audit. Each record should capture the date, content covered, and which staff members completed the session. No record means no proof.

Frequency is not fixed, but training must keep pace with regulatory changes, emerging typologies, and shifts in your business's own risk profile.

For lawyers and accountants entering the regime under Tranche 2, this component deserves immediate attention. Staff unfamiliarity with ML/TF indicators is a pattern AUSTRAC identifies early in enforcement reviews. A practical starting point is understanding warning signs accountants should pay attention to before your first regulated client interaction.

Component 3: Employee Due Diligence

Training equips staff to recognise external threats. Employee due diligence addresses the risk from within.

AUSTRAC identifies insider facilitation as a genuine vulnerability across regulated industries, and why this matters for AML compliance is well documented: employees with access to systems, funds, or customer data can enable money laundering in ways no external control can catch. This component requires documented procedures, not informal practices.

At minimum, your program must document procedures for:

  • Background screening of prospective employees

  • Reference checking prior to appointment

  • Assessing personal financial circumstances where they could create a conflict or vulnerability

The depth of screening must be proportionate to role. Staff with transaction approval authority, access to customer funds, or responsibility for compliance functions require more thorough vetting than employees with no financial exposure. A blanket approach does not satisfy the risk-based intent of the AML/CTF rules.

Critically, due diligence does not end at hiring. The 2026 reforms formalise ongoing personnel due diligence as a continuous obligation. Your procedures must address how the business monitors for changes in employee behaviour or personal circumstances that could signal emerging ML/TF risk throughout employment.

All employee due diligence records must be retained under your broader record-keeping obligations and referenced explicitly within the AML/CTF program documentation.

Component 4: Program Adoption and Oversight

Accountability must extend upward from employee-level risks. The AML/CTF program must be formally adopted by the governing body of the reporting entity through a board resolution, partnership agreement, or equivalent documented decision; informal sign-off does not satisfy the obligation.

Adoption is not a one-time event. The governing body must maintain a documented process for receiving AML/CTF performance information on an ongoing basis, meaning scheduled reporting, minuted discussions, and recorded decisions.

The governance structure must assign three distinct layers of responsibility:

  • Governing body: ultimate accountability for the program

  • Senior manager: day-to-day operational responsibility

  • AML/CTF Compliance Officer (covered in Component 5): dedicated compliance functions

Each layer must be named and described in the program documentation. Where accountability lines are ambiguous, AUSTRAC can treat that ambiguity as a standalone compliance gap, separate from any substantive failure.

For smaller businesses entering under Tranche 2, including sole-director companies and small partnerships, the governing body function may concentrate in a single person. The documentation standard does not reduce accordingly. The program must name that person, describe the oversight role they hold, and record how they exercise it. If your business is a sole practitioner, understanding why integrated compliance support matters before enrolment opens on 31 March 2026 is worth the lead time.

Component 5: AML/CTF Compliance Officer

Once the governing body has formally adopted the program, a named individual must own its day-to-day operation.

Every reporting entity must appoint a named AML/CTF Compliance Officer. The role must be assigned to a specific individual; documented ownership by a single person is what creates the accountable oversight the framework requires. The role can sit with an existing senior employee rather than a dedicated hire, but it must be documented and assigned to one person.

That person must report to the governing body at least annually, delivering a written assessment of the program's effectiveness. An undocumented verbal update does not satisfy this requirement.

Day-to-day responsibilities include:

  • Monitoring for suspicious activity and overseeing SMR submissions

  • Ensuring staff training is completed and recorded

  • Keeping the program current as AUSTRAC guidance and regulations change

Seniority matters. Naming a junior administrator without escalation authority does not satisfy the intent of this requirement, even if the paperwork is correct. The Compliance Officer must have genuine authority, access to relevant information, and the standing to act on findings.

For Tranche 2 entities, this appointment should happen well before the 31 March 2026 enrolment opening. The role requires lead time to understand obligations, configure reporting workflows, and document procedures before the business accepts its first regulated customer. If you are evaluating how to resource this function, how to choose the right AML compliance provider outlines the key considerations.

Component 6: Independent Review

Once the Compliance Officer is in place, the program needs an independent check that the whole framework is actually working.

AUSTRAC requires the AML/CTF program to be independently reviewed at regular intervals to assess whether it remains effective, current, and proportionate to the entity's real risk profile. This is not a self-assessment. The reviewer must not be the person who designed or operates the program. That structural requirement typically means engaging an external compliance specialist, a qualified auditor, or an internal reviewer who sits entirely outside the AML function.

Frequency is risk-adjusted rather than fixed. AUSTRAC expects reviews to occur regularly, with higher-risk entities generally reviewing every two to three years. Any significant business change, such as a new product line, entry into a new market, or an ownership restructure, should trigger an ad-hoc review regardless of the standard cycle.

Critically, the review must produce documented findings. A review that generates no written output, or whose report sits unread on a shelf, does not satisfy the requirement. The governing body must receive the findings and act on any recommendations.

Those findings then feed directly into the Compliance Officer's mandatory annual report to the governing body. Connecting these two components creates a traceable, continuous audit trail demonstrating that the program is genuinely improving, not just nominally maintained.

Component 7: AUSTRAC Feedback Procedures

Reviewing and acting on AUSTRAC's published guidance is a distinct program obligation, not an extension of the independent review component covered above.

Reporting entities must maintain documented procedures for receiving, reviewing, and actioning communications from AUSTRAC. This includes financial crime typology reports, sector-specific risk assessments, and regulatory updates. Ignoring these publications is not a passive oversight; it is a documented compliance failure that AUSTRAC can cite during a review.

AUSTRAC publishes guidance that directly affects what a compliant program looks like in practice. When a new typology report identifies emerging ML/TF methods in your sector, or a sector risk assessment shifts the threat landscape, your program must reflect that shift.

The feedback procedure must assign ownership to a named role. The Compliance Officer is the appropriate owner in most entities. Their documented responsibilities should include:

  • Monitoring AUSTRAC's website and communications channels for new publications

  • Assessing whether each publication requires updates to the ML/TF Risk Assessment, due diligence procedures, or training materials

  • Recording that review and any resulting actions taken

When AUSTRAC guidance changes sector risk settings, the ML/TF Risk Assessment and KYC procedures may require direct revision as a result.

This component is consistently underdocumented in smaller entities' programs. A named owner, a defined monitoring cadence, and a log of how guidance has been reviewed and responded to strengthens both the program and the audit trail available to AUSTRAC.

Component 8: Reporting Procedures

Where AUSTRAC feedback procedures focus on receiving regulatory guidance, reporting procedures govern what your business does when a reportable event actually occurs.

Documented procedures are mandatory for all three AUSTRAC-mandated report types:

  • Suspicious Matter Reports (SMRs): required when staff identify a transaction or customer behaviour that raises ML/TF suspicion

  • Threshold Transaction Reports (TTRs): required for cash transactions that meet the applicable reporting threshold under the AML/CTF Act

  • International Funds Transfer Instructions (IFTIs): required where applicable to your designated services

SMR procedures must map the full internal escalation pathway: staff identification, Compliance Officer review, and submission via the AUSTRAC Online portal. The tipping-off prohibition applies at every stage. Staff must know they cannot disclose to the customer or any third party that an SMR has been filed or is under consideration.

TTR procedures must name who is responsible for identifying reportable transactions, confirm the submission timeframe, and specify how submitted report records are retained.

All reporting procedures should include threshold definitions, decision trees for ambiguous cases, and AUSTRAC Online portal contact details so staff can act immediately without escalating for basic guidance.

Reporting failures are among the most common grounds for AUSTRAC enforcement action. Documented, tested procedures remove reliance on individual judgment and create a defensible compliance record.

Component 9: AUSTRAC Enrolment Maintenance

Reporting obligations don't end with submitting the right reports. Enrolment with AUSTRAC is a parallel, ongoing obligation that many entities treat as a one-time administrative step rather than a live compliance requirement.

Reporting entities must keep enrolment details accurate and current at all times. Any change to business structure, ownership, designated services offered, or contact information must be reflected in AUSTRAC's records promptly. AUSTRAC uses enrolment data to determine the scope of each entity's obligations and to direct supervisory activity, so outdated details aren't merely an administrative gap; they can misrepresent what the business is actually doing and attract incorrect or missed regulatory scrutiny.

Failing to update enrolment when circumstances change is a compliance breach in its own right, separate from any program deficiency.

For Tranche 2 entities, enrolment opens 31 March 2026. Internal program documentation should be well advanced before that date, not built afterwards.

The AML/CTF program must include documented procedures that:

  • Assign a named role responsible for monitoring and updating enrolment details

  • Define clear triggers for review, including adding a designated service, changing a director, or restructuring the business

Finally, enrolment records should be reconciled during the independent program review to confirm that what AUSTRAC holds on file accurately reflects the entity's current operating profile.

Component 10: KYC Procedures and the Tiered Due Diligence Framework

Once enrolment details are current, KYC is where compliance becomes operational.

AUSTRAC requires a tiered, risk-based approach to customer due diligence across three levels:

  • Simplified Due Diligence for demonstrably lower-risk customers

  • Standard Due Diligence for the majority of customer relationships

  • Enhanced Due Diligence (EDD) for higher-risk customers, including politically exposed persons (PEPs), high-value transaction customers, and those from higher-risk jurisdictions

Your documented KYC procedures must be specific enough for any staff member to apply consistently. Referring to "verifying customer identity" without specifying acceptable documents, verification methods, or escalation thresholds does not meet AUSTRAC's standard.

For corporate and trust customers, verifying the entity itself is insufficient. AUSTRAC requires identification of the natural persons who ultimately own or control the entity, making beneficial ownership a discrete procedural requirement.

For Tranche 2 entities, transitional relief applies to clients engaged before 1 July 2026, who are exempt from immediate KYC requirements unless a suspicious matter arises or the service risk profile changes. That window exists to phase in verification systems, not to defer them indefinitely.

Platforms such as Personr centralise identity verification, document collection, and KYC workflows, supporting consistent, audit-ready processes across all customer types without fragmented tooling.

Component 11: Ongoing Customer Due Diligence

KYC establishes a customer's risk profile at onboarding; OCDD is the obligation to keep that profile accurate over time.

Under the AML/CTF Act, reporting entities must monitor customer relationships and transactions on an ongoing basis to confirm activity remains consistent with the customer's known risk profile and expected behaviour. A static onboarding assessment does not satisfy this requirement.

Triggers for re-screening and review include changes in transaction patterns, customer circumstances, or external risk indicators. Your program must document when re-screening is required, how updated information is requested, and who is responsible for escalating anomalies.

Screening scope matters. AML screening must cover sanctions lists, PEP databases, and adverse media. A customer who was low risk at onboarding can become high risk following a subsequent sanctions listing or adverse reputational development. Your program must be configured to detect and act on those post-onboarding changes.

Transaction monitoring must be calibrated to your specific risk profile and customer base. Thresholds, flags, and review triggers must be documented and regularly tested for effectiveness; generic settings that do not reflect your actual customer population create detection gaps and unnecessary false positives.

For businesses managing large customer volumes, OCDD is operationally demanding. Centralised platforms that automate screening and surface risk changes in real time reduce manual workload while strengthening detection, which is precisely where Personr's ongoing monitoring capability adds practical value.

Component 12: Record Keeping

All the monitoring activity covered in Component 11 only delivers compliance value if the records it generates are properly retained and retrievable.

The AML/CTF Act sets two core retention periods: 7 years from the end of the customer relationship for customer identification records, and 7 years from the date of the transaction for transaction records.

Retention alone is insufficient. AUSTRAC requires records to be retrievable within a reasonable timeframe on request. Disorganised or inaccessible records constitute a compliance failure even where the underlying activity was conducted correctly.

Records that must be kept include:

  • KYC and customer verification documents

  • Customer risk assessments

  • Transaction records

  • SMR and TTR submissions

  • Staff training records

  • Independent review findings

  • The AML/CTF program itself, including all previous versions with the dates each version was in force

Record-keeping procedures must be documented within the program, not managed informally. The documentation must assign named responsibility for storage and retrieval, and address data security in line with the Privacy Act 1988 obligations that apply concurrently. The Australian Privacy Principles govern how customer information is stored, accessed, and protected across the retention period.

AUSTRAC publishes a dedicated record-keeping checklist. Entities should map their current practices against it and close any gaps before an audit or formal AUSTRAC request arises.

What Tranche 2 Reforms Mean for Newly Regulated Businesses

The 12 components covered above apply to every reporting entity, but Tranche 2 makes them newly relevant to thousands of Australian businesses that have never held AUSTRAC obligations before.

For the sectors newly brought into scope under Tranche 2, the compliance starting point is identical to that of long-regulated entities. Enrolment opens 31 March 2026, but the obligation to have a compliant program in place exists before a business provides a designated service, not after it registers. That distinction matters: enrolment is administrative; program readiness is the substantive requirement.

One transitional relief measure applies. Clients engaged before 1 July 2026 are exempt from immediate KYC verification unless suspicious activity arises or the nature of the service materially changes. That window gives newly regulated businesses time to phase in verification procedures for existing relationships without immediate breach exposure.

AUSTRAC has signalled active supervision of Tranche 2 sectors. Businesses that wait until after enrolment to begin building their programs are creating enforcement risk on a compressed timeline.

Building a New Program vs. Maintaining an Existing One

Whether your business is newly regulated or has held AUSTRAC obligations for years, the 12-component framework applies in full; the difference is where you start.

New programs must have all 12 components documented, formally adopted by the governing body, and operationally embedded before the business accepts its first regulated customer. Skipping even one creates a documented gap that AUSTRAC can identify on inspection. There is no grace period for incomplete programs once a designated service is being provided.

Existing programs carry a different risk: not absence, but drift. Documentation drift occurs when written policies no longer match operational practice, either because procedures evolved without corresponding updates, or because staff turnover severed the link between documented policy and day-to-day behaviour. The program looks complete on paper while the actual controls have quietly diverged.

Consolidating program management onto a centralised platform addresses this directly. Personr covers KYC, KYB, AML screening, ongoing monitoring, policy hosting, risk assessments, and reporting in one place, making the documented program and the operational record the same system of truth rather than parallel artefacts that gradually fall out of sync.

The Compliance Officer should treat the 12-component framework as the agenda for their mandatory annual governing-body report.

What a Compliant AML/CTF Program Actually Looks Like

Whether you are finalising a program that has been in place for years or building one from scratch ahead of Tranche 2 enrolment, the standard is the same.

A compliant AML/CTF program is specific, documented, risk-based, and operationally embedded. It names people, assigns responsibilities, sets thresholds, and produces records AUSTRAC can inspect. A policy document that sits unread on a shared drive is not compliance; it is paperwork.

As established throughout this guide, all 12 components carry equal legal weight regardless of entity size. The practical starting sequence is straightforward:

  • Complete your ML/TF Risk Assessment first. It informs every other component, from due diligence thresholds to training content.

  • Appoint your Compliance Officer. This person is accountable for keeping the entire program current and reporting to the governing body at least annually.

  • Build each remaining component outward from those two foundations.

Use AUSTRAC's published guidance and checklists as your primary references. Supplement them with a platform that keeps your documented policies and your actual operational practice in the same system, so they cannot drift apart.

If gaps exist in your current program, address them now. "We were working on it" is not a defence AUSTRAC accepts.

Conclusion

An AML/CTF compliance program is not a formality. It is a legal obligation with 12 distinct, mandatory components that every reporting entity must address in writing, regardless of size or industry.

The key takeaways are straightforward: your ML/TF Risk Assessment drives everything else; your Compliance Officer owns accountability; your program must be documented, operational, and regularly reviewed; and Tranche 2 reforms mean thousands of businesses need to act now.

Compliance is not a project you finish once. It is a continuous discipline that requires the right people, the right processes, and the right records.

If your program has gaps, close them before AUSTRAC finds them for you. Start with your risk assessment, appoint your officer, and build from there. The framework is clear. The timeline is real. The only variable is how prepared your business chooses to be.

Get started with Personr in three easy steps

1

Book a call

Book a call with our compliance experts. We’ll set you up with a free account ready to suit your team’s needs.

2

Add your people

From new clients to your existing ones, onboard effortlessly with our self-serve platform.

3

Dedicated onboarding

From navigating local laws to support for your team members, our dedicated team will help you get set up seamlessly.

Get started with Personr in three easy steps

1

Book a call

Book a call with our compliance experts. We’ll set you up with a free account ready to suit your team’s needs.

2

Add your people

From new clients to your existing ones, onboard effortlessly with our self-serve platform.

3

Dedicated onboarding

From navigating local laws to support for your team members, our dedicated team will help you get set up seamlessly.

Get started with Personr in three easy steps

1

Book a call

Book a call with our compliance experts. We’ll set you up with a free account ready to suit your team’s needs.

2

Add your people

From new clients to your existing ones, onboard effortlessly with our self-serve platform.

3

Dedicated onboarding

From navigating local laws to support for your team members, our dedicated team will help you get set up seamlessly.