Under Section 36 of the Australian AML/CTF Act 2006, establishing and maintaining an ongoing employee training program is a mandatory compliance requirement. If your business provides designated services, you must ensure that all relevant staff are trained to understand their compliance obligations, recognize red flags, and handle suspicious activity.

Whether you manage a law firm, accounting practice, real estate agency, conveyancing firm, trust and company service provider (TCSP), precious metals dealership, or virtual asset service provider (VASP), your employees represent your first line of defence against financial crime. This guide outlines who must receive training, what topics must be covered, and how to document the training to satisfy AUSTRAC requirements.

Is Employee Training Legally Required?

Yes. Every reporting entity must implement a written AML/CTF Program. **Part A** of this program must include an employee due diligence program (for screening staff) and an ongoing employee training program. Failing to implement an ongoing training program is a direct breach of the AML/CTF Rules, exposing your business to civil penalties and audit failures.

AUSTRAC expects your training to be **risk-based and ongoing**. It is not sufficient to train employees once during onboarding and never revisit the material; training must be updated regularly to reflect changes in your business's risk profile and the broader regulatory landscape.

Who Must Receive AML Training?

You must deliver AML/CTF training to all employees, contractors, and directors whose duties relate to the provision of a designated service. This includes:

Note: Even temporary staff or contractors who handle client onboarding or transaction processing must receive training before they begin providing designated services.

What Topics Must Training Cover?

An effective training program must be tailored to the specific risks of your business, but at a minimum, it should cover the following core topics:

  1. Money Laundering and Terrorism Financing Concepts: Explain what ML/TF is, how criminals exploit professional services (using real-world typologies), and the social and economic impact of financial crime.
  2. Your Legal Obligations: An overview of the AML/CTF Act, the role of AUSTRAC, and the specific designated services your firm provides.
  3. The Written AML/CTF Program: Walk staff through your firm's specific compliance policies, including KYC verification, risk rating, and record-keeping procedures.
  4. Identifying Red Flags: Educate staff on how to spot suspicious transactions, unusual client behaviour, or high-risk transaction structures.
  5. Suspicious Matter Reporting (SMR): Explain the process for escalating a suspicion internally to the Compliance Officer, and the strict timelines for reporting.
  6. Tipping-Off Prohibition: Emphasise that staff must never reveal to a client or any third party that a suspicion has been recorded or an SMR has been submitted.

Important: The tipping-off prohibition is a criminal offence. Training must ensure that all staff understand they cannot discuss suspicious activity reports with clients under any circumstances.

Industry-Specific Red Flags

Training should cover red flags specific to your sector:

How to Document and Maintain Records

If AUSTRAC audits your business, they will request evidence of your employee training. You must maintain a detailed **Training Register** containing:

All training records must be retained securely for a minimum of 7 years.

Keep Your Team Trained and Compliant

CompliDesk includes built-in staff training logs and registers, making it easy to assign training, track completions, and maintain audit-ready records for AUSTRAC.

Start free today

Frequently Asked Questions

Is AML/CTF training legally required for all Tranche 2 staff in Australia?
Yes, training is legally required for all employees, contractors, and officers whose duties relate to the provision of a designated service. Receptionists, support staff, and senior management must all receive training tailored to their roles.
How often must AML compliance training be updated for staff?
AUSTRAC recommends delivering refresher training at least once every 12 months. Additional training must be provided whenever there are material changes to your AML/CTF Program, your business model, or the AML/CTF legislation.
Does training have to be in-person, or can it be done online?
Training can be delivered in-person, online via e-learning modules, or through a hybrid approach. The key requirement is that the training is documented, assessed, and specifically tailored to the risks of your business.

Related reading: What your AML/CTF Program must include · 15 common AML compliance mistakes · Managing AML compliance for multiple clients · Frequently asked questions