You need an AML/CTF program in place and operating, not drafted and shelved. Every reporting entity must adopt and maintain one, and that has applied to the firms captured by Tranche 2 since 1 July 2026. A reporting entity is any firm that provides a designated service, one of the services listed in s6 of the Act, from conveyancing to dealing in precious metals and stones to creating or restructuring a company or trust. If that describes your firm, the program is not optional, and it is not a document you file away and forget.
If you have read older guidance, one thing has changed shape. The Part A and Part B split is pre-reform framing. It described the regime that ended on 30 June 2026 and should not be used for your current obligations. Under the reformed regime a program is two things: a written ML/TF risk assessment, and the policies that act on what the assessment found. The content the old Part A and Part B carried is all still required. It now hangs off the risk assessment rather than sitting in two labelled halves.
What the program must contain
The risk assessment comes first, because everything else is calibrated to it. It is the written view of where money laundering and terrorism financing risk actually sits in your firm: across the services you provide, the customers you take on, the channels you deliver through, and the countries your money moves through. A program whose policies are not traceable to a risk the assessment identified is a template, and it will read as one.
The policies then have to cover more than identity checks. You need employee due diligence, so the people who will handle your obligations are vetted before they start and monitored while they work. You need a named AML/CTF compliance officer, the AMLCO, the person responsible for the program’s day to day operation; appointing one carries its own eligibility and independence constraints. You need risk awareness training, so the staff who see transactions can recognise a red flag when one appears. You need applicable customer identification procedures: the KYC steps you run when a customer comes in, covered in detail on the customer due diligence page. And you need ongoing customer due diligence: monitoring the customers you already have and keeping their information current.
The program is also where you document how the firm will meet its reporting obligations, such as suspicious matter and threshold transaction reports, and how it will keep the records the Act requires. A program that says nothing about reporting leaves your biggest obligations unmanaged.
Enhanced customer due diligence needs its own written procedure, and it is not optional just because you have no obviously high-risk customers today. It sets out what triggers the enhanced checks, what extra information you collect, how you verify source of funds and source of wealth rather than taking them at face value, and how the outcome is recorded. It has to exist because it describes what you will do when a high-risk customer appears. The day one arrives is the wrong day to design the procedure.
| What the program holds | What it must cover |
|---|---|
| ML/TF risk assessment | Your services, customer types, delivery channels and country exposure, with a rating and the reasoning behind it |
| Personnel policies | Employee due diligence, a named AML/CTF compliance officer, risk awareness training |
| Customer policies | Customer identification, ongoing due diligence, the enhanced procedures for higher-risk customers |
| Maintenance policies | How reporting obligations are met, how records are kept, how the program is reviewed and independently evaluated |
Who approves the program
Adoption is a decision, and it has to be made and shown. Your governing body, meaning the partners, the directors or the committee that runs the firm, approves the program. The approval is recorded in the minutes or in a dated resolution, and the approved version is the one that counts. The AMLCO operates the program and keeps it current, but approval is not delegated to them. That distinction matters at review time, because the independent evaluation examines who adopted the program, what they approved, and when, as well as whether the content holds up.
Adopt means the program was formally made yours by the people who run the firm. Maintain means it stays aligned with what the firm actually does, which is the harder half: services change, staff change, the risk picture changes, and each change is a reason to revisit the document.
How often you review it
How often you formally review the program is worth pinning down rather than assuming. You should revisit it whenever something real changes: a new service, a new customer type, a new delivery channel, a new jurisdiction, or a change in the law. Beyond that, the program is tested on a cycle through the independent evaluation, which is itself a requirement. In most firms the AMLCO drafts the review, the governing body considers it, and the independent evaluation provides the external check. Plan for each review to be scheduled, dated and recorded the same way the original approval was, so the program reads as a living document with a trail behind it.
What catches people out
A template downloaded and renamed is not a program. The policies have to describe what your firm will actually do, and the test is whether the content fits your services, your customers and your risk assessment, not whether the document resembles a model. The giveaways are generic: no named roles, no firm-specific services, no dates, no version. Run a firm on a generic template and the consequence is blunt: you are a reporting entity with no program in the eyes of the Act. You bought a document. You did not adopt a program.
An approval with no record is no approval. The governing body can resolve to adopt the program and never minute it, or a principal can approve it in an email nobody keeps. At the first independent evaluation, and in any AUSTRAC inspection, the approval is one of the first things examined: who adopted the program, when, and which version. Without a record you can show none of that, and a well-written program collapses to an unadopted draft.
The enhanced procedures are what firms skip when nobody looks high-risk. When the customer base is ordinary, the temptation is to treat them as a later task and let the everyday policies stand for the whole obligation. The consequence arrives the first time a customer does trigger enhanced checks: there is no agreed procedure to run, staff improvise under time pressure, and the record of the decision is whatever someone remembers to write down. The program was incomplete from day one, and the gap is visible to any reviewer.
What is still unsettled
The AML/CTF Rules 2025 are newly in force and carry the detailed content under new numbering. The old rule numbers no longer apply, so any specific rule reference you find in older guidance has to be re-checked against the current Rules before it goes into your program. That caution matters more than usual here, because a great deal of published material still describes the pre-reform structure. If a source you are reading talks about Part A and Part B, it is describing the regime that ended on 30 June 2026, and its rule references will be stale too.
The frequency of formal review is the second open question. It is not a fixed period in the Act, so confirm it against the Rules and AUSTRAC’s guidance before you write a review cycle into your procedure. The independent evaluation runs on its own clock of at least every three years, covered on the independent evaluation page.
Where to start
- Start from the risk assessment: write down the designated services you provide, the customers you take on, how the services are delivered and where the money moves. Both parts of the program are built on that document, so a reviewer can see the reasoning behind every procedure.
- Write both parts as procedures, not restatements: for each content item, name who does the step and what they do, from the customer due diligence checks at onboarding to the enhanced checks for higher-risk customers. If a sentence survives having your firm’s name deleted, it is not a procedure yet.
- Approve it, record it, and give it a test date: the governing body adopts the program at a meeting, the decision is minuted with the version and the date, and the independent evaluation is scheduled so the program has a formal review point. Then check that the AMLCO has the access and the authority the program assumes they have.
How duely handles this
The program is built through a wizard rather than a blank template, with the sections parameterised on your vertical, and it is versioned: a draft supersedes the approved version only when it is approved, and the superseded version stays on file. Approval is gated rather than advisory. duely refuses to approve a program while no AMLCO is appointed, while the approver’s own personnel due diligence is out of date, or while a required section is unanswered. The output is a PDF stamped with a hash of the answers behind it, so a later reviewer can tell whether the document matches the record it came from.