Call it an audit and you will search under the wrong name. The current requirement is an independent evaluation of your AML/CTF program, the written set of policies, procedures and controls your firm keeps to meet the Act’s obligations, and the check tests the program as written and as run. It binds every reporting entity, the Act’s term for a business that provides a designated service, one of the services the Act lists such as assisting in a conveyance or creating or restructuring a company or trust. Under Tranche 2 that means accountants, legal practitioners, conveyancers, real estate agents, dealers in precious metals and stones, and trust and company service providers, all of whom became reporting entities on 1 July 2026.
The rename is recent, and it decides which material you can trust. The AML/CTF Amendment Act 2024 reshaped the requirement, and the AML/CTF Rules were remade in 2025 with new numbering, so guidance written before 2024, which commonly called this step an audit, needs rechecking against the current text. AUSTRAC’s develop-your-AML/CTF-program guidance now calls the step “conduct an independent evaluation”. If your program document still says “independent audit”, fix the wording while you revisit the program anyway; see what an AML/CTF program must contain for the program’s required parts.
An evaluation is not a renewal of your enrolment and it is not a one-off health check. It is a standing part of the program’s life cycle, and four questions decide whether yours is on track: what it must cover, who can perform it, how often, and where the findings go.
What an independent evaluation actually checks
An evaluation works on two layers of the program. Design is the program as written: your risk assessment, your customer due diligence (CDD) procedures, the checks you run on a customer’s identity and on who ultimately owns or controls them, your reporting arrangements, and your record-keeping, set out in a way that matches the work you actually take on. Operation is the program as practised: whether staff follow the written procedures, whether the risk assessment still fits the business you now run, and whether the controls produce the records the Act requires. An evaluation that only reads the document misses half the job, and one that only watches the practice cannot tell you whether the design is sound. AUSTRAC’s program starter kit policy documents are the working reference for the expected scope.
In practice, operation testing means tracing work rather than reading policy. The evaluator follows a customer file from the first identity check to a filed report, compares the risk rating assigned at onboarding with the one the file carries later, and checks whether the people named in the procedures are the people actually making the decisions. These are the kinds of questions the starter kit guidance points to, not a checklist the Act prescribes.
| Question | Requirement | Source |
|---|---|---|
| What must the evaluation cover? | The design of the program and its operation in practice: risk assessment, CDD, reporting, record-keeping | Act s26F(4)(f); Rules s 5-10 |
| Who can perform it? | Someone independent of the program’s design and operation; not necessarily an external firm, but not your AMLCO or a member of the compliance team | s26F(4)(f); Rules s 5-10; AUSTRAC independent evaluation guidance |
| How often? | Your policies set the frequency, appropriate to the nature, size and complexity of your business. At a minimum, at least once every 3 years | Act ss 26F(4)(f) and 116; staggered first-evaluation deadlines in the AML/CTF Transitional Rules 2026 |
| What happens to the findings? | Reported to the governing body, which decides and records what to change | AUSTRAC program starter kit policy documents; adverse findings recorded on the Independent Evaluation Response form |
The first row is the substance of the evaluation. The evaluator reads the program against your actual business, tests whether the written procedures produce the records the Act requires, and looks for the gap between what the program promises and what it delivers. That gap is where most findings come from, and the distinction between the two layers matters because the fixes differ: a program that is followed badly needs supervision and training, one that cannot be followed needs a rewrite.
The second row is the one firms misread. Independence is measured against the program’s design and operation, not against the firm. An employee can be independent of the program; an external consultant can be tangled up in it. What disqualifies a candidate is a hand in writing the procedures, running them, or deciding how they are applied. Being a partner does not disqualify anyone, and being junior does not qualify anyone; the question is what the person did in relation to the program, not where they sit. That is why the AML/CTF compliance officer (the AMLCO), the person your firm appoints to oversee the program, is usually the wrong choice; the page on appointing an AMLCO covers the role’s conflicts in more detail. The candidate also has to know the Act and your business well enough to judge the program against both, which narrows the field in a small firm.
The third row is the cycle. Guidance before the rewrite pointed to at least every three years , and whether the current instrument keeps that cadence is one of the items duely must confirm before publishing. Treat the first evaluation as part of your first cycle after 1 July 2026, not as a response to something AUSTRAC asks for.
The fourth row is what makes the evaluation count. The report goes to your governing body, the board, the partners, or the principals who approve the program in the first place. The governing body decides what to change and records its decisions, and both the report and the decisions are records you retain for seven years. An evaluation that ends in a PDF in a folder has not been completed; it has been filed.
What catches people out
Three mistakes repeat across firms, and each carries a price.
Naming the AMLCO because they know the program best. Independence is measured against the program’s design and operation, and the AMLCO sits inside both. The evaluation fails the test, and if it is ever scrutinized the record shows the person being evaluated chose their own reviewer. The price is a redo: a second evaluation by someone with no part in the program’s design or operation, on your time and at your cost.
The second mistake is treating the report as the deliverable. The obligation does not end when the evaluator hands over the report; it ends when the governing body has considered the findings and decided what to change. A report that never reaches the board, the partners, or the principals leaves the program’s weaknesses intact, and it leaves you with an evaluation record that shows exactly that.
The third mistake is assuming the evaluator must come from outside, or must come from inside. Independence does not require an external firm in every case, and it does not allow an interested insider either. Firms that assume external spend money they may not need to spend and push the evaluation past its cycle. Firms that assume internal skip the independence check and produce an evaluation that does not count. The test is the same in both directions: no hand in the design, no hand in the operation, and a documented basis for the choice, because an evaluation that cannot show why its reviewer was independent is an evaluation that cannot defend itself.
What is still unsettled
The detail of the requirement is the part that changed most recently, so this page flags it rather than asserting it. Whether the operative independent-evaluation requirement now sits in the Act or in the AML/CTF Rules 2025 is not settled in this draft, and if it sits in the Rules 2025 the rule number needs confirming. The frequency is flagged the same way: guidance before the rewrite pointed to at least every three years, and the current cycle, plus when the first evaluation falls due for a firm whose obligations began on 1 July 2026, needs checking against the current text . The expectation that findings go to the governing body is also flagged. One further open question: whether a significant change to the business, such as a new service line or a re-rated risk profile, pulls an evaluation forward before the regular cycle.
Where to start
If your program is new, three things are worth doing now, because they make the eventual evaluation cheaper and more honest:
- Name the conflict early: work out who is clear of the program’s design and operation. In most small firms that rules out the AMLCO, so decide who the fallback is before you need them.
- Fix the terminology and the cycle: if the program document still calls this an audit, update the wording, and record the interval you intend to follow once the current cycle is confirmed.
- Route the findings before they exist: agree now that the evaluation report goes to the governing body and that its decisions are minuted. That is the difference between an evaluation and a paper exercise.
How duely handles this
duely tracks the evaluation deadline on the at-least-three-yearly cycle and surfaces it on the compliance calendar alongside every other dated obligation. Quarterly effectiveness checks run across SMR and UAR handling, CDD, ECDD, TTR and CBM, with a corrective-action and re-test loop, so the evaluation has something to examine other than the program document. One boundary: duely tracks the evaluation and holds its findings. It does not perform it, and an evaluation performed by the platform would not be independent of the program it evaluates.