Every AUSTRAC reporting entity must have a written AML/CTF program. Under the reformed AML/CTF Act 2006, this program must be approved by senior management and updated as your business and the regulatory environment change. Here's what must be included.
The two parts of an AML/CTF program
AUSTRAC's rules divide AML/CTF programs into two parts:
Part A โ General obligations: Covers your firm's overall AML/CTF risk management approach, governance structure, oversight by senior management, and independent program evaluation (at least every 3 years).
Part B โ Customer Due Diligence: Covers how you identify and verify customers, ongoing monitoring procedures, and enhanced due diligence for higher-risk clients.
What Part A must include
- Your ML/TF risk assessment โ identification of the money laundering and terrorism financing risks your business faces
- Risk-based policies and procedures to manage those risks
- Your AML/CTF Compliance Officer's details and responsibilities
- Board and senior management oversight arrangements
- Staff AML/CTF training program and records
- Independent review processes
- SMR and TTR reporting procedures
What Part B must include
- Customer identification and verification procedures (KYC/KYB)
- Customer risk assessment methodology
- Ongoing CDD procedures โ how you monitor the relationship
- Enhanced Due Diligence procedures for higher-risk customers (PEPs, high-risk jurisdictions, complex structures)
- Procedures for customers who cannot be identified
- Record-keeping requirements
ML/TF risk assessment โ the foundation
Everything in your AML/CTF program should flow from your risk assessment. You must identify the specific money laundering and terrorism financing risks your business faces โ based on your customer types, the services you provide, delivery channels, and the jurisdictions you operate in.
Staff training requirements
All staff who deal with customers or handle transactions must receive AML/CTF training appropriate to their role. Training must be provided when staff join and regularly thereafter. Training records must be maintained.
How often must the program be reviewed?
Your program must be reviewed at least every 3 years by an independent reviewer โ someone who is not involved in day-to-day compliance. It must also be updated whenever there are significant changes to your business, customer base, or the regulatory environment.
CompliDesk helps all Tranche 2 entities stay compliant.
Whether you're a lawyer, accountant, real estate agent, conveyancer or TCSP โ CompliDesk guides you through every step of your AUSTRAC obligations. Sign up free today.
Sign up free todayRelated reading: AUSTRAC enrolment checklist ยท AUSTRAC record keeping requirements ยท AML employee training requirements ยท Frequently asked questions