Introduction

From 1 July 2026, tens of thousands of Australian businesses are required to have a written AML/CTF programme in place. That includes accountants, lawyers, real estate agents, conveyancers, trust and company service providers, and dealers in precious metals. If you have been focused on getting enrolled with AUSTRAC, the programme itself may not have made it onto your list yet. Enrolment is the starting point, not the finish line.

An AML/CTF programme is a documented, risk-based framework that explains how your business identifies, assesses, and manages its exposure to money laundering and terrorism financing. Under the AML/CTF Act, it has two mandatory parts. This guide walks through what each part requires, how to build it, and what AUSTRAC expects to see.

NameScan has been providing AML screening solutions to businesses across 195 countries since 2014, and has helped thousands of newly regulated entities get their compliance foundations in place. The framework below draws on AUSTRAC’s published guidance and the practical experience of businesses going through this process for the first time.

What Is an AML/CTF Programme?

An AML/CTF programme is the central compliance document for any AUSTRAC reporting entity. It is not a policy memo or a list of good intentions. It is a working framework that governs how your business operates in a regulated environment.

AUSTRAC requires that the programme be approved by your governing body (typically a principal, director, or board) and reviewed regularly. It must be proportionate to your business’s size, the services you offer, and the ML/TF risks those services create. A sole-practitioner accountant will produce a different programme from a national real estate network, and AUSTRAC expects that difference to be visible in the document.

The programme has two mandatory parts:

  • Part A: Your risk-based framework, covering how you identify and manage money laundering and terrorism financing risks
  • Part B: Your customer due diligence (CDD) procedures, covering how you verify customers and monitor the relationship over time

Part A: Building Your Risk Framework

Part A is the foundation. It requires your business to think systematically about the ML/TF risks it faces and document how it manages them. AUSTRAC has moved away from tick-box compliance. The expectation is that your risk assessment reflects the reality of your business, not a generic template.

Step 1: Conduct Your ML/TF Risk Assessment

Start with a risk assessment that covers four areas: your customers, the services you provide, the transaction types you handle, and the geographies you operate in. For each area, ask which parts of your business present the greatest exposure to money laundering or terrorism financing.

For a real estate agent, the customer dimension might include foreign buyers, investors using trust structures, or buyers paying large deposits from unexpected sources. For an accountant, the service dimension might include trust account management, company formations, or transactions involving offshore entities. Document each risk area, assign a rating (low, medium, or high), and record your reasoning.

AUSTRAC provides sector-specific starter kits for real estate agents, accountants, lawyers, and other Tranche 2 sectors. These include pre-populated risk assessment templates you can customise. Using them is not mandatory, but they are a sensible starting point.

Step 2: Define Your Risk Appetite and Controls

Once you have identified your risks, Part A requires you to document how you will manage them. This means setting out:

  • The controls in place to mitigate each risk (identity verification, PEP screening, sanctions checks, transaction monitoring).
  • Your risk appetite, including what risk levels you will accept and what triggers a higher level of scrutiny or a refusal of business.
  • Who in your business is responsible for AML/CTF compliance (your Compliance Officer) and what their responsibilities are.

Step 3: Document Your Training Programme

Part A must also cover how you train staff. Everyone with a role in customer-facing work, onboarding, or transaction processing needs role-appropriate AML/CTF training. AUSTRAC provides free educational resources, so a formal training provider is not required. What matters is that training happens, is documented, and is updated when obligations or risk profiles change.

Step 4: Set Out Your Independent Review Process

AUSTRAC requires that your AML/CTF programme be independently reviewed at appropriate intervals. For smaller businesses, this can be handled by a competent external party rather than a dedicated internal audit function. The review should assess whether the programme is effective, whether it reflects your current risk profile, and whether it complies with the AML/CTF Rules. Document the review schedule and record the outcomes each time.

Part B: Building Your Customer Due Diligence Procedures

Part B covers how your business identifies and verifies its customers. It is the practical day-to-day compliance work: verifying who customers are, checking them against sanctions lists and PEP databases, and monitoring the relationship over time.

Step 5: Define When CDD Is Required

Under the AML/CTF Rules, CDD must be completed before you provide a designated service. For real estate agents, this is typically when a listing agreement is signed (for sellers) or when a buyer engages you to find a property. For accountants, it is before you begin providing any of the designated services that bring you into scope. Part B must document the precise point at which CDD commences for each type of service your business provides.

Step 6: Document Your Verification Process

CDD involves collecting and verifying identity information. For individual customers, this typically includes name, date of birth, residential address, and identity document details (passport, driver’s licence). For companies, trusts, and other legal entities, it extends to identifying and verifying the ultimate beneficial owners (UBOs), the natural persons who own or control the entity. Part B must specify what documents or data sources you use for verification, the standards they need to meet, and how you record and store the outcome.

Step 7: Establish Your PEP and Sanctions Screening Process

Every CDD process under AUSTRAC’s AML/CTF Rules must include screening for politically exposed persons (PEPs) and sanctions. A PEP is someone who holds or has held a prominent public function: government ministers, senior military officers, senior executives of state-owned enterprises, and their close family members and associates. If a customer is identified as a PEP, enhanced due diligence (EDD) is required. If a customer appears on a sanctions list, providing them with a service is prohibited.

Part B must set out how you conduct these checks (manually or through an automated screening tool), and how you handle matches and false positives. NameScan’s pay-as-you-go screening platform lets Tranche 2 entities run PEP, sanctions, and adverse media checks on demand with full audit trails, with no subscription required.

Step 8: Set Up Ongoing Monitoring

CDD is not a one-off check. Once a customer is onboarded, you are required to monitor the relationship for changes in risk. This includes re-screening against PEP and sanctions databases when profiles change, updating customer information when it becomes outdated, and watching for transactions or behaviour inconsistent with the customer’s stated purpose. Part B must document how often you re-screen customers, what triggers an out-of-cycle review, and how you escalate concerns to your Compliance Officer.

Pulling It Together: What AUSTRAC Expects to See

AUSTRAC has been clear that it does not expect perfection on day one. What it expects is demonstrated effort: a programme clearly tailored to your business, showing you have thought through your risks and giving your staff enough guidance to act on them.

The programme should be a living document. Review it when your business changes, when regulation changes, and at least annually. Document each review and any updates you make. The practical test: if AUSTRAC asked your Compliance Officer to walk through the programme tomorrow, would the answers be in the document?

Next Steps

Building an AML/CTF programme is not complicated, but it does require time and attention. Start with AUSTRAC’s sector-specific starter kit for your industry, customise it to your business, get it approved by your governing body, and use it to train your staff before obligations commence.

For the customer due diligence component, you will need a reliable, auditable screening solution. Manual searches do not meet AUSTRAC’s standards and do not scale. NameScan provides pay-as-you-go PEP, sanctions, and adverse media screening that generates audit-ready results from the first check.

Frequently Asked Questions

What are the two parts of an AML/CTF programme?

An AML/CTF programme under Australia’s AML/CTF Act has two mandatory parts. Part A is the risk-based framework: it covers your ML/TF risk assessment, the controls in place to manage those risks, your governance structure including the appointment of a Compliance Officer, your staff training programme, and your independent review schedule. Part B is your customer due diligence (CDD) procedure: it sets out how and when you verify customer identities, how you screen for PEPs and sanctions, and how you conduct ongoing monitoring throughout the customer relationship.

Does my AML/CTF programme need to be approved?

Yes. Under the AML/CTF Act, your programme must be approved by the governing body of your business: typically the principal, director, or board. It must also be reviewed and updated at appropriate intervals. AUSTRAC expects the programme to be a genuine operational document, not one sitting in a drawer. Evidence that your governing body has reviewed and approved the programme is part of what AUSTRAC will look for during any examination or audit.

Can I use AUSTRAC’s starter kit as my AML/CTF programme?

AUSTRAC’s sector-specific starter kits are templates designed to help smaller, lower-risk businesses build their programmes. They are a legitimate starting point but not a finished product. You must customise the starter kit to reflect your business’s specific risk profile, the services you provide, and the controls you have in place. Submitting an unmodified starter kit would not satisfy AUSTRAC’s requirement for a programme proportionate to your actual business.

How often does my AML/CTF programme need to be reviewed?

The AML/CTF Act requires that your programme be reviewed regularly and updated when it is no longer adequate. AUSTRAC’s guidance points to a minimum annual review, with additional reviews triggered by material changes to your business (new services, new customer types, new geographies), changes to the AML/CTF Rules, or findings from your independent review. Document each review and the outcome, even if no changes were required.

Do I need an AML/CTF programme if I only occasionally provide designated services?

Yes. If you provide any designated service, regardless of how often, you are a reporting entity under the AML/CTF Act and you must have a programme in place before you provide that service after 1 July 2026. There is no minimum volume threshold. The obligation is triggered by the nature of the service, not how frequently you offer it. AUSTRAC’s starter kits are designed specifically for businesses with limited designated service activity.

Need to run PEP, sanctions, and adverse media checks for your AML programme? NameScan is a pay-as-you-go platform with no subscription required and no minimum spend. Start your first check in minutes: namescan.io