Under Section 36 of the Australian AML/CTF Act 2006, establishing and maintaining an ongoing employee training program is a mandatory compliance requirement. If your business provides designated services, you must ensure that all relevant staff are trained to understand their compliance obligations, recognize red flags, and handle suspicious activity.
Whether you manage a law firm, accounting practice, real estate agency, conveyancing firm, trust and company service provider (TCSP), precious metals dealership, or virtual asset service provider (VASP), your employees represent your first line of defence against financial crime. This guide outlines who must receive training, what topics must be covered, and how to document the training to satisfy AUSTRAC requirements.
Is Employee Training Legally Required?
Yes. Every reporting entity must implement a written AML/CTF Program. **Part A** of this program must include an employee due diligence program (for screening staff) and an ongoing employee training program. Failing to implement an ongoing training program is a direct breach of the AML/CTF Rules, exposing your business to civil penalties and audit failures.
AUSTRAC expects your training to be **risk-based and ongoing**. It is not sufficient to train employees once during onboarding and never revisit the material; training must be updated regularly to reflect changes in your business's risk profile and the broader regulatory landscape.
Who Must Receive AML Training?
You must deliver AML/CTF training to all employees, contractors, and directors whose duties relate to the provision of a designated service. This includes:
- Customer-facing staff: Receptionists who collect client ID, sales agents, paralegals, property managers, customer support agents, and consultants.
- Operational staff: Staff who process payments, manage trust accounts, or handle company and trust formations.
- Compliance staff: The AML/CTF Compliance Officer and any internal audit or risk management staff.
- Senior Management: Directors and partners who must approve compliance policies and oversee the risk framework.
Note: Even temporary staff or contractors who handle client onboarding or transaction processing must receive training before they begin providing designated services.
What Topics Must Training Cover?
An effective training program must be tailored to the specific risks of your business, but at a minimum, it should cover the following core topics:
- Money Laundering and Terrorism Financing Concepts: Explain what ML/TF is, how criminals exploit professional services (using real-world typologies), and the social and economic impact of financial crime.
- Your Legal Obligations: An overview of the AML/CTF Act, the role of AUSTRAC, and the specific designated services your firm provides.
- The Written AML/CTF Program: Walk staff through your firm's specific compliance policies, including KYC verification, risk rating, and record-keeping procedures.
- Identifying Red Flags: Educate staff on how to spot suspicious transactions, unusual client behaviour, or high-risk transaction structures.
- Suspicious Matter Reporting (SMR): Explain the process for escalating a suspicion internally to the Compliance Officer, and the strict timelines for reporting.
- Tipping-Off Prohibition: Emphasise that staff must never reveal to a client or any third party that a suspicion has been recorded or an SMR has been submitted.
Important: The tipping-off prohibition is a criminal offence. Training must ensure that all staff understand they cannot discuss suspicious activity reports with clients under any circumstances.
Industry-Specific Red Flags
Training should cover red flags specific to your sector:
- Legal & Conveyancing: Clients using multiple trust accounts, purchasing property with no clear source of wealth, or requesting rapid transactions with no obvious commercial purpose.
- Accounting: Unexplained changes in business cash flows, requests to structure transactions just below the $10,000 threshold, or shell companies with no active trade.
- Real Estate: Buyers offering large cash payments, using third-party offshore entities, or purchasing properties significantly above market value.
- Precious Metals & Stones: Customers purchasing bullion using structured cash payments, or refusing to provide ID when transactions exceed $10,000.
- VASPs: Transactions originating from darknet markets, mixing services, or sanctioned wallet addresses.
How to Document and Maintain Records
If AUSTRAC audits your business, they will request evidence of your employee training. You must maintain a detailed **Training Register** containing:
- The name and role of each employee who attended.
- The date the training was completed.
- The topics covered (including copy of the training materials).
- Assessment results (to prove the staff understood the material).
All training records must be retained securely for a minimum of 7 years.
Keep Your Team Trained and Compliant
CompliDesk includes built-in staff training logs and registers, making it easy to assign training, track completions, and maintain audit-ready records for AUSTRAC.
Start free todayFrequently Asked Questions
Related reading: What your AML/CTF Program must include · 15 common AML compliance mistakes · Managing AML compliance for multiple clients · Frequently asked questions