Australian AML/CTF · Explainer

How do the three AML governance roles differ?

Separate oversight, approval and daily coordination so that each decision has an owner.

General information only, not legal, compliance, or other professional advice. Does not confirm compliance.

Start with: Does AML regulation follow your service or your profession?

Name the functions first

An AML/CTF governance chart should explain decisions, not merely list job titles. The governing body oversees the business’s approach, senior managers make specified approvals, and the compliance officer coordinates day-to-day compliance. AUSTRAC’s guidance also emphasises resources and direct reporting of important findings. A small business may combine roles, but the functions remain distinct. Map each function to the person who actually has the authority to perform it. A title alone does not show that the arrangement works.

Three governance functionsConnected concepts. Lines do not show ownership or a reporting hierarchy. Governing body: Oversight and resources. Senior manager: Specified decisions and approvals. Compliance officer: Daily oversight and coordination.Governing body Senior manager Compliance officer
  • Governing body

    Oversight and resources.

  • Senior manager

    Specified decisions and approvals.

  • Compliance officer

    Daily oversight and coordination.

Three governance functions

Functions may be combined where the applicable conditions are met.

Connected concepts. Lines do not show ownership or a reporting hierarchy.

Give each issue a route

A practical design separates three questions: who investigates an issue, who approves the response and who receives oversight information. For example, a recurring intake failure may need operational repair, a policy change and a report about the wider risk. One email marked for everyone can leave all three tasks unclear. Use a simple issue record with named owners and decision dates. Make escalation possible when the operational team cannot resolve a problem within its authority or available resources.

Example: an unresolved backlog

Suppose staff report a growing backlog of customer reviews. The compliance officer gathers facts and explains the effect on controls. A responsible manager decides the operational response within the applicable procedures. The governing body considers whether resources and oversight are adequate. This is an illustrative division of work, not a complete rule for every backlog. The point is that receiving a report is different from approving a policy or completing an individual customer review. Each step needs an identifiable output.

Check authority in practice

Test the chart with a recent issue rather than only asking whether all names are filled in. Could the compliance officer obtain the needed records? Did the decision maker have authority? Did significant findings reach the governing body intact? Record the changes needed to make the route usable. Link the chart to role descriptions, absence cover and meeting arrangements. Review it when staff or business structure change, so a departure does not leave an important function assigned to a person who no longer performs it.

Check reporting quality

Ask whether governance reports distinguish open issues, completed actions and untested claims of improvement. A report that lists activity alone may hide whether controls work. Use clear evidence labels so decision makers can see what is known, what remains uncertain and which resource or policy decision they are being asked to make.

Sources and scope

Sources checked on 2026-09-06. This page is not continuously updated. Check the linked legislation and AUSTRAC guidance for current requirements.

  • Governing body

    AUSTRAC · Web guidance checked 6 September 2026; no immutable version supplied

This page does not cover: All conditions for combining roles in sole traders and micro businesses.

Common AML/CTF terms