Skip to content
Tranche 2 guide

Independent evaluation: scope and timing

Your AML/CTF program needs a regular independent evaluation, run by someone with no part in its design or operation, with findings to your governing body.

By the duely Compliance Team

Call it an audit and you will search under the wrong name. The current requirement is an independent evaluation of your AML/CTF program, the written set of policies, procedures and controls your firm keeps to meet the Act’s obligations, and the check tests the program as written and as run. It binds every reporting entity, the Act’s term for a business that provides a designated service, one of the services the Act lists such as assisting in a conveyance or creating or restructuring a company or trust. Under Tranche 2 that means accountants, legal practitioners, conveyancers, real estate agents, dealers in precious metals and stones, and trust and company service providers, all of whom became reporting entities on 1 July 2026.

The rename is recent, and it decides which material you can trust. The AML/CTF Amendment Act 2024 reshaped the requirement, and the AML/CTF Rules were remade in 2025 with new numbering, so guidance written before 2024, which commonly called this step an audit, needs rechecking against the current text. AUSTRAC’s develop-your-AML/CTF-program guidance now calls the step “conduct an independent evaluation”. If your program document still says “independent audit”, fix the wording while you revisit the program anyway; see what an AML/CTF program must contain for the program’s required parts.

An evaluation is not a renewal of your enrolment and it is not a one-off health check. It is a standing part of the program’s life cycle, and four questions decide whether yours is on track: what it must cover, who can perform it, how often, and where the findings go.

What an independent evaluation actually checks

An evaluation works on two layers of the program. Design is the program as written: your risk assessment, your customer due diligence (CDD) procedures, the checks you run on a customer’s identity and on who ultimately owns or controls them, your reporting arrangements, and your record-keeping, set out in a way that matches the work you actually take on. Operation is the program as practised: whether staff follow the written procedures, whether the risk assessment still fits the business you now run, and whether the controls produce the records the Act requires. An evaluation that only reads the document misses half the job, and one that only watches the practice cannot tell you whether the design is sound. AUSTRAC’s program starter kit policy documents are the working reference for the expected scope.

In practice, operation testing means tracing work rather than reading policy. The evaluator follows a customer file from the first identity check to a filed report, compares the risk rating assigned at onboarding with the one the file carries later, and checks whether the people named in the procedures are the people actually making the decisions. These are the kinds of questions the starter kit guidance points to, not a checklist the Act prescribes.

QuestionRequirementSource
What must the evaluation cover?The design of the program and its operation in practice: risk assessment, CDD, reporting, record-keepingAct s26F(4)(f); Rules s 5-10
Who can perform it?Someone independent of the program’s design and operation; not necessarily an external firm, but not your AMLCO or a member of the compliance teams26F(4)(f); Rules s 5-10; AUSTRAC independent evaluation guidance
How often?Your policies set the frequency, appropriate to the nature, size and complexity of your business. At a minimum, at least once every 3 yearsAct ss 26F(4)(f) and 116; staggered first-evaluation deadlines in the AML/CTF Transitional Rules 2026
What happens to the findings?Reported to the governing body, which decides and records what to changeAUSTRAC program starter kit policy documents; adverse findings recorded on the Independent Evaluation Response form

The first row is the substance of the evaluation. The evaluator reads the program against your actual business, tests whether the written procedures produce the records the Act requires, and looks for the gap between what the program promises and what it delivers. That gap is where most findings come from, and the distinction between the two layers matters because the fixes differ: a program that is followed badly needs supervision and training, one that cannot be followed needs a rewrite.

The second row is the one firms misread. Independence is measured against the program’s design and operation, not against the firm. An employee can be independent of the program; an external consultant can be tangled up in it. What disqualifies a candidate is a hand in writing the procedures, running them, or deciding how they are applied. Being a partner does not disqualify anyone, and being junior does not qualify anyone; the question is what the person did in relation to the program, not where they sit. That is why the AML/CTF compliance officer (the AMLCO), the person your firm appoints to oversee the program, is usually the wrong choice; the page on appointing an AMLCO covers the role’s conflicts in more detail. The candidate also has to know the Act and your business well enough to judge the program against both, which narrows the field in a small firm.

The third row is the cycle. Guidance before the rewrite pointed to at least every three years , and whether the current instrument keeps that cadence is one of the items duely must confirm before publishing. Treat the first evaluation as part of your first cycle after 1 July 2026, not as a response to something AUSTRAC asks for.

The fourth row is what makes the evaluation count. The report goes to your governing body, the board, the partners, or the principals who approve the program in the first place. The governing body decides what to change and records its decisions, and both the report and the decisions are records you retain for seven years. An evaluation that ends in a PDF in a folder has not been completed; it has been filed.

What catches people out

Three mistakes repeat across firms, and each carries a price.

Naming the AMLCO because they know the program best. Independence is measured against the program’s design and operation, and the AMLCO sits inside both. The evaluation fails the test, and if it is ever scrutinized the record shows the person being evaluated chose their own reviewer. The price is a redo: a second evaluation by someone with no part in the program’s design or operation, on your time and at your cost.

The second mistake is treating the report as the deliverable. The obligation does not end when the evaluator hands over the report; it ends when the governing body has considered the findings and decided what to change. A report that never reaches the board, the partners, or the principals leaves the program’s weaknesses intact, and it leaves you with an evaluation record that shows exactly that.

The third mistake is assuming the evaluator must come from outside, or must come from inside. Independence does not require an external firm in every case, and it does not allow an interested insider either. Firms that assume external spend money they may not need to spend and push the evaluation past its cycle. Firms that assume internal skip the independence check and produce an evaluation that does not count. The test is the same in both directions: no hand in the design, no hand in the operation, and a documented basis for the choice, because an evaluation that cannot show why its reviewer was independent is an evaluation that cannot defend itself.

What is still unsettled

The detail of the requirement is the part that changed most recently, so this page flags it rather than asserting it. Whether the operative independent-evaluation requirement now sits in the Act or in the AML/CTF Rules 2025 is not settled in this draft, and if it sits in the Rules 2025 the rule number needs confirming. The frequency is flagged the same way: guidance before the rewrite pointed to at least every three years, and the current cycle, plus when the first evaluation falls due for a firm whose obligations began on 1 July 2026, needs checking against the current text . The expectation that findings go to the governing body is also flagged. One further open question: whether a significant change to the business, such as a new service line or a re-rated risk profile, pulls an evaluation forward before the regular cycle.

Where to start

If your program is new, three things are worth doing now, because they make the eventual evaluation cheaper and more honest:

  1. Name the conflict early: work out who is clear of the program’s design and operation. In most small firms that rules out the AMLCO, so decide who the fallback is before you need them.
  2. Fix the terminology and the cycle: if the program document still calls this an audit, update the wording, and record the interval you intend to follow once the current cycle is confirmed.
  3. Route the findings before they exist: agree now that the evaluation report goes to the governing body and that its decisions are minuted. That is the difference between an evaluation and a paper exercise.

How duely handles this

duely tracks the evaluation deadline on the at-least-three-yearly cycle and surfaces it on the compliance calendar alongside every other dated obligation. Quarterly effectiveness checks run across SMR and UAR handling, CDD, ECDD, TTR and CBM, with a corrective-action and re-test loop, so the evaluation has something to examine other than the program document. One boundary: duely tracks the evaluation and holds its findings. It does not perform it, and an evaluation performed by the platform would not be independent of the program it evaluates.

Common questions

Do I need an external firm to evaluate my AML/CTF program?
Not necessarily. The evaluator must be independent of the program's design and operation, but independence does not require an outside firm in every case. An employee who had no part in writing or running the program can perform the evaluation, if they can judge it against the Act. Document why they qualify.
How often must an AML/CTF program be evaluated?
Your AML/CTF policies set the frequency, and it must be appropriate to the nature, size and complexity of your business. At a minimum an independent evaluation must occur at least once every 3 years (Act ss 26F(4)(f) and 116). To manage demand after 1 July 2026, the AML/CTF Transitional Rules 2026 stagger the deadline for a newly regulated firm's first evaluation, so check which staggered date applies to you. AUSTRAC suggests going earlier than the 3-year deadline anyway, partly because evaluators with the right skills will be easier to book.
Can the AMLCO evaluate the AML/CTF program?
Usually not. The evaluation must be independent of the program's design and operation, and the AMLCO typically designs or runs the program, so they fail the test. If the person being evaluated chooses their own reviewer, the evaluation does not count and you redo it with someone with no part in the program's design or operation.
What happens to the findings of an independent evaluation?
The findings go to your governing body, not just into a file. The governing body decides what to change, approves the changes to the program, and records its decisions. The report and those decisions are records you retain for seven years. An evaluation whose findings never reach decision-makers has not been completed.
What does an independent evaluation of an AML/CTF program cover?
It covers the design and the operation of the program. Design is your written risk assessment, customer due diligence, reporting and record-keeping procedures. Operation is whether staff actually follow them and whether the procedures produce the records the Act requires. AUSTRAC's program starter kit policy documents set the expected scope.

This is one obligation of many

Take the 2-minute readiness assessment to see the full set that applies to your firm, or book a walkthrough and watch one matter run from scoping to a finished evidence pack.