Skip to content
Tranche 2 guide

What an AML/CTF program must contain

An AML/CTF program is a written ML/TF risk assessment plus the policies that act on it, approved by a senior manager and reviewed at least every 3 years.

By the duely Compliance Team

You need an AML/CTF program that is in place and operating. Every reporting entity must adopt and maintain one, and the firms captured by Tranche 2 have been bound by that since 1 July 2026. A reporting entity is any firm that provides a designated service, one of the services listed in s6 of the Act, from conveyancing to dealing in precious metals and stones to creating or restructuring a company or trust. If that describes your firm, the program is not optional, and it is not a document you file away and forget.

If you have read older guidance, note one change of structure. The Part A and Part B split is pre-reform framing. It described the regime that ended on 30 June 2026 and should not be used for your current obligations. Under the reformed regime a program is two things: a written ML/TF risk assessment, and the policies that act on what the assessment found. The content the old Part A and Part B carried is all still required. It now flows from the risk assessment rather than sitting in two labelled halves.

What the program must contain

The risk assessment comes first, because everything else is calibrated to it. It is the written view of where money laundering and terrorism financing risk actually sits in your firm: across the services you provide, the customers you take on, the channels you deliver through, and the countries your money moves through. A program whose policies are not traceable to a risk the assessment identified is a template, and it will read as one.

The policies then have to cover more than identity checks. You need employee due diligence, so the people who will handle your obligations are vetted before they start and monitored while they work. You need a named AML/CTF compliance officer, the AMLCO, the person responsible for the program’s day-to-day operation; appointing one carries its own eligibility and independence constraints. You need risk awareness training, so the staff who see transactions can recognise a red flag when one appears. You need applicable customer identification procedures: the identity verification and screening steps you run when a customer comes in, covered in detail on the customer due diligence page. And you need ongoing customer due diligence: monitoring the customers you already have and keeping their information current.

The program is also where you document how the firm will meet its reporting obligations, such as suspicious matter and threshold transaction reports, and how it will keep the records the Act requires. A program that says nothing about reporting leaves your biggest obligations unmanaged.

Enhanced customer due diligence needs its own written procedure, and it is not optional just because you have no obviously high-risk customers today. It sets out what triggers the enhanced checks, what extra information you collect, how you verify source of funds and source of wealth rather than taking them at face value, and how the outcome is recorded. It has to exist because it describes what you will do when a high-risk customer appears. The day one arrives is the wrong day to design the procedure.

What the program holdsWhat it must cover
ML/TF risk assessmentYour services, customer types, delivery channels and country exposure, with a rating and the reasoning behind it
Personnel policiesEmployee due diligence, a named AML/CTF compliance officer, risk awareness training
Customer policiesCustomer identification, ongoing due diligence, the enhanced procedures for higher-risk customers
Maintenance policiesHow reporting obligations are met, how records are kept, how the program is reviewed and independently evaluated

Who approves the program

Adoption is a decision, and it has to be made and shown. A senior manager approves the ML/TF risk assessment and the AML/CTF policies, and every update to either (Act s26P(1)). A senior manager is someone who makes, or takes part in making, decisions that affect the whole or a substantial part of the business (s5), and your policies must name who holds that responsibility (s26F(4)(c)). AUSTRAC’s guidance is that the senior manager has to do this personally and cannot delegate it. Updates to the risk assessment must also be notified in writing to the governing body as soon as practicable (s26P(2)), whose role is ongoing oversight (s26H). Record the approval with the version and the date: the approved version is the one that counts. The AMLCO operates the program and keeps it current, but approval is not theirs unless they are also the named senior manager. That distinction matters at review time, because the independent evaluation examines who adopted the program, what they approved, and when, as well as whether the content holds up.

Adopt means the program was formally made yours by the people who run the firm. Maintain means it stays aligned with what the firm actually does, which is the harder half: services change, staff change, the risk picture changes, and each change is a reason to revisit the document.

How often you review it

The Act sets a floor. The risk assessment must be reviewed at least once every 3 years, and also when there is a significant change to your services, customers, delivery channels or jurisdictions, and when AUSTRAC communicates risk information relevant to you (s26D(1)). The policies must be reviewed at least once every 3 years as well (s26F(3)(d)), and the AML/CTF Rules 2025 require them to be reviewed after any risk assessment review and after an independent evaluation with adverse findings. The independent evaluation runs on its own cycle of at least every 3 years. In most firms the AMLCO drafts the review and a senior manager approves the result. Plan for each review to be scheduled, dated and recorded the same way the original approval was, so the program reads as a living document with a trail behind it.

What catches people out

A template downloaded and renamed is not a program. The policies have to describe what your firm will actually do, and the test is whether the content fits your services, your customers and your risk assessment, not whether the document resembles a model. The giveaways are generic: no named roles, no firm-specific services, no dates, no version. Run a firm on a generic template and, in the eyes of the Act, you are a reporting entity with no program. Buying a document is not adopting a program.

An approval with no record is no approval. A senior manager can approve the program in a meeting nobody minutes, or in an email nobody keeps. At the first independent evaluation, and in any AUSTRAC inspection, the approval is one of the first things examined: who adopted the program, when, and which version. Without a record you can show none of that, and a well-written program collapses to an unadopted draft.

Firms skip the enhanced procedures when nobody looks high-risk. When the customer base is ordinary, the temptation is to treat those procedures as a later task and let the everyday policies stand for the whole obligation. The consequence arrives the first time a customer does trigger enhanced checks: there is no agreed procedure to run, staff improvise under time pressure, and the record of the decision is whatever someone remembers to write down. The program was incomplete from day one, and the gap is visible to any reviewer.

What is still unsettled

The AML/CTF Rules 2025 are newly in force and carry the detailed content under new numbering. The old rule numbers no longer apply, so any specific rule reference you find in older guidance has to be re-checked against the current Rules before it goes into your program. That caution matters more than usual here, because a great deal of published material still describes the pre-reform structure. If a source you are reading talks about Part A and Part B, it is describing the regime that ended on 30 June 2026, and its rule references will be stale too.

The minimum review frequency is settled: at least once every 3 years for both the risk assessment and the policies (Act ss 26D(1)(b) and 26F(3)(d)), with earlier reviews on the triggers above. What each firm still has to decide is what counts as a “significant change” for its own business, so write your own triggers into the policies. The independent evaluation runs on its own cycle of at least every 3 years, covered on the independent evaluation page.

Where to start

  1. Start from the risk assessment: write down the designated services you provide, the customers you take on, how the services are delivered and where the money moves. Both parts of the program are built on that document, so a reviewer can see the reasoning behind every procedure.
  2. Write both parts as procedures, not restatements: for each content item, name who does the step and what they do, from the customer due diligence checks at onboarding to the enhanced checks for higher-risk customers. If a sentence survives having your firm’s name deleted, it is not a procedure yet.
  3. Approve it, record it, and give it a review date: the named senior manager approves the risk assessment and policies, the approval is recorded with the version and the date, the governing body is told, and the next review (no later than 3 years) and the independent evaluation are scheduled. Then check that the AMLCO has the access and the authority the program assumes they have.

How duely handles this

The program is built through a wizard rather than a blank template, with the sections parameterised on your vertical, and it is versioned: a draft supersedes the approved version only when it is approved, and the superseded version stays on file. Approval is gated rather than advisory. duely refuses to approve a program while no AMLCO is appointed, while the approver’s own personnel due diligence is out of date, or while a required section is unanswered. The output is a PDF stamped with a hash of the answers behind it, so a later reviewer can tell whether the document matches the record it came from.

Common questions

What are the two parts of an AML/CTF program?
A written ML/TF risk assessment, and the policies that act on it. The policies cover employee due diligence, your AML/CTF compliance officer, training, customer identification, ongoing due diligence, the enhanced checks for higher-risk customers, how you meet your reporting obligations, and how records are kept. The Part A and Part B split people remember is pre-reform framing and no longer describes the obligation.
Who has to approve my AML/CTF program?
A senior manager, meaning someone who makes or takes part in decisions affecting the whole or a substantial part of the business, approves the ML/TF risk assessment and the AML/CTF policies, and every update to them (Act s26P(1)). Your policies name who that is (s26F(4)(c)), and the approval should be recorded. An unapproved program, or one whose approval cannot be shown, is difficult to defend in an independent evaluation or an AUSTRAC inspection.
Is a template AML/CTF program enough?
No. A template is a starting point. The program has to be written for your firm's actual risk: your designated services, your customers, your delivery methods and your jurisdictions. A downloaded template that has not been tailored to any of those is not a program in AUSTRAC's eyes, because it does not describe what you will actually do.
How often do I need to review my AML/CTF program?
At least once every 3 years, and sooner when something triggers it. The Act requires the risk assessment to be reviewed after a significant change, after AUSTRAC communicates relevant risk information, and in any event at least once every 3 years (s26D(1)), and the policies to be reviewed at least once every 3 years too (s26F(3)(d)). The AML/CTF Rules 2025 add triggers, including an independent evaluation with adverse findings.
What happens if I don't have an AML/CTF program?
Providing a designated service without a program in place is a breach of the AML/CTF Act 2006 (Cth). AUSTRAC can take enforcement action, which can include remedial directions, infringement notices or prosecution. The absence of a program also shows up immediately in any review, because it is the first document asked for.

Where this happens in duely

This is how the obligation above looks as a record your team keeps while the work happens.

See the AML/CTF program builder

AML/CTF program

Illustrative

  • Version 4 Changes in progress Draft
  • Version 3 Current authorised version Approved
  • Version 2 Kept in the history Superseded
  • AMLCO appointment Recorded in the program On record
  • PDF export With a SHA-256 hash Ready
One authorised version at a time, with every earlier version and approval kept.

This is one obligation of many

Take the 2-minute readiness assessment to see the full set that applies to your firm, or book a walkthrough and watch one engagement run from scoping to a finished evidence pack.