Pricing Privacy Act About Get Started Free
AUSTRAC compliance guide

What is an AML/CTF program? A plain English guide for professional services firms

Every Australian business that becomes a reporting entity under the AML/CTF Act must have a written AML/CTF program. But what does that actually mean, and what must it contain?

The simple version

An AML/CTF program is a written document that describes how your firm identifies and manages the risk that its services could be used for money laundering or terrorism financing. Think of it as your firm's AML compliance manual.

It doesn't need to be long. AUSTRAC has explicitly said that programs should be proportionate to the size and risk profile of the business. A sole practitioner accounting firm does not need the same program as a large bank.

The key test: Does your program actually reflect how your firm manages AML risk in practice? AUSTRAC is looking for genuine compliance, not a document that sits in a drawer.

What must an AML/CTF program include?

AUSTRAC requires every program to cover seven key areas:

1. Risk assessment

A documented assessment of the ML/TF risks your firm faces — based on your client types, services, delivery methods, and geographies. This is the foundation of everything else. If you don't understand your risks, you can't manage them.

2. Customer due diligence (CDD) procedures

How does your firm verify who clients are before providing services? Your program must document your KYC process — what you collect, how you verify it, what triggers enhanced due diligence, and how you handle clients who can't be verified.

3. Ongoing monitoring

How do you monitor client relationships and transactions for suspicious activity after onboarding? This includes what you look for, how often you review client risk, and what triggers re-verification.

4. Suspicious matter reporting

When and how does your firm decide to lodge a Suspicious Matter Report (SMR)? Your program must document the process — including who makes the decision, who is authorised to lodge, and how tipping-off is prevented.

5. Record keeping

What records do you keep, where are they stored, how are they secured, and how long are they retained? AUSTRAC requires 7 years minimum.

6. Staff training

How will staff be trained on AML/CTF obligations? When does training occur, who is responsible for it, and how is completion documented?

7. Program review

How and when will the program be reviewed? AUSTRAC expects at least annual reviews, plus reviews when significant changes occur in the business or the regulatory environment.

Part A vs Part B programs

AUSTRAC structures a program in two parts: Part A covers your risk management approach (the seven areas above) — your risk assessment, governance, monitoring, reporting systems, and staff due diligence. Part B covers your customer identification procedures — how you collect and verify KYC information for customers and beneficial owners, including PEP checks. Every program must include a Part B section; most small professional services firms will also need a Part A section unless a specific AUSTRAC exemption applies.

How long does it take to write one?

Starting from scratch, a properly documented AML/CTF program for a small accounting firm typically takes 8–20 hours to prepare. Using templates and software, this can be reduced to 2–4 hours per firm. CompliDesk generates a pre-filled, AUSTRAC-aligned program draft for each client in minutes — based on their risk profile and service scope.

Manage AML compliance for all your clients from one dashboard

CompliDesk is built specifically for Australian professional services firms managing AML/CTF compliance for clients. Sign up free for free signup.

Sign up free today

AML/CTF Programs — quick answers

AUSTRAC's guidance structures it as Part A (covering your ML/TF risk awareness, policies, and procedures) and Part B (covering your customer identification procedures). In practice it's one program with two required components, not two separate unrelated documents.
A generic template alone won't satisfy AUSTRAC — your program must reflect your specific business, services, client base, and risk profile. Software that generates a program tailored to the actual details you provide is a safer approach than adapting someone else's document.
At minimum annually, and immediately after any material change to your business — new services, new client types, a regulatory update, or a significant risk event. A program that's never been revisited since it was written is itself a compliance red flag if AUSTRAC ever reviews it.