Australian AML/CTF · Explainer

When does an AML program become a working process?

Connect the written program to staff actions, decisions and evidence.

General information only, not legal, compliance, or other professional advice. Does not confirm compliance.

Start with: Does AML regulation follow your service or your profession?

Treat the program as a system of work

An AML/CTF program is more than a stored policy document. AUSTRAC’s overview connects risk assessment and policies with governance, approval, daily operation, monitoring and review. A template can help organise the work, but the business must connect it to its own services and processes. A Starter Kit does not confirm compliance. Ask what staff do differently because a policy exists. If the answer is unclear, the document may not yet provide a usable instruction for the people delivering services.

Turn a policy into a working instructionFollow the process from top to bottom. Policy trigger: State when staff must act. Person and information: Identify who receives the case and what they need. Decision and response: Return the decision to the person handling the customer. Record and check: Keep the result and inspect a sample file.Policy trigger Person and information Decision and response Record and check
  1. Policy trigger

    State when staff must act.

  2. Person and information

    Identify who receives the case and what they need.

  3. Decision and response

    Return the decision to the person handling the customer.

  4. Record and check

    Keep the result and inspect a sample file.

Turn a policy into a working instruction

Illustrative implementation exercise. A documented policy needs a working process; this sequence is not a complete evaluation method.

Follow the process from top to bottom.

Trace one policy into practice

Choose a policy requirement and follow it through the customer process. Identify the trigger, the person who acts, the information used, the decision and the record produced. Then inspect a sample file to see whether those elements are present. This is a suggested implementation exercise, not a complete evaluation method. It can expose practical gaps such as missing access, an unclear handover or a form that does not capture the information staff need to follow the approved procedure.

Example: an escalation rule

Suppose a policy tells staff to escalate unresolved information. To make it operational, the firm identifies who receives the case, what staff must include and how the decision returns to the person handling the customer. It also identifies what happens while the issue remains unresolved. The example is intentionally about a process, not a particular legal trigger. A short, tested instruction can be more useful than a long paragraph that leaves staff to invent the route each time.

Maintain the connection

When you update a policy, update the related forms, system prompts and staff instructions. Record the approved version and check whether the revised process works after introduction. Use incidents and recurring questions to identify where instructions need attention. Keep the business risk assessment connected to the controls it supports, so changes in services do not leave old procedures in place by accident. The aim is a traceable relationship between the risk, the approved response and the evidence of what staff actually did.

Use staff questions as evidence

Ask staff to explain one procedure in their own words and show where they record the result. Differences can reveal unclear instructions or training needs. Correct the source of the confusion and check again on a later sample. The exercise tests usability; it is not a substitute for independent evaluation.

Sources and scope

Sources checked on 2026-09-06. This page is not continuously updated. Check the linked legislation and AUSTRAC guidance for current requirements.

This page does not cover: A complete AML/CTF program for your business.

Common AML/CTF terms