Australian AML/CTF · Explainer

How to assess an AML software provider

Test AML software against your own procedures, customer cases and record needs before you buy it.

General information only, not legal, compliance, or other professional advice. Does not confirm compliance.

Start with: When does an AML program become a working process?

Start with the task the product supports

AUSTRAC suggests checking a product’s fit with Australian obligations, your industry and existing procedures. It also recommends understanding its limits and support. Its general RegTech factsheet predates the current reforms. Ask the supplier to identify the current requirements its product supports and the functions outside its scope. AUSTRAC does not recommend or endorse a specific RegTech product.

Test the product before buyingFollow the process from top to bottom. Describe a case: Use fictional information and an expected result. Run the test: Include missing data and failed checks. Inspect the record: Retrieve the decision history and export. Record the gap: Separate tested functions from promises.Describe a case Run the test Inspect the record Record the gap
  1. Describe a case

    Use fictional information and an expected result.

  2. Run the test

    Include missing data and failed checks.

  3. Inspect the record

    Retrieve the decision history and export.

  4. Record the gap

    Separate tested functions from promises.

Test the product before buying

Suggested review structure. Completing these steps does not confirm compliance.

Follow the process from top to bottom.

Suggested demonstration: follow one case

Prepare fictional cases before the demonstration. Include a straightforward individual, a more complex customer relevant to your business and a case with missing information. Ask staff to enter the case, correct a mistake, pass it to a reviewer and retrieve its history. Write the expected result before the supplier runs the test. This is a suggested purchasing exercise, not a regulatory test suite.

Test a failure as well as a successful check

Ask what staff see when an external check times out or returns an uncertain result. Can they tell the difference between a completed check and a failed request? Ask the supplier to demonstrate that difference. For a screening feature, ask how a possible match reaches the person who must assess it. A reassuring colour on a screen is not an explanation of the result.

Inspect configuration and records

Ask who can change a rule, whether approval is needed and how staff can see earlier settings. Request a sample export using fictional records. Open it outside the product and check whether the case history still makes sense. Ask which attachments, reasons and dates are included. These are suggested checks; the record requirements that apply to your business need a separate assessment.

Test the exported record outside the softwareFollow the process from top to bottom. Fictional case: Create a sample case with evidence, a decision and an attachment. Export: Request the case history and supporting records. Independent reading: Open the export outside the product. Check whether the reasons, dates and evidence remain understandable.Fictional case Export Independent reading
  1. Fictional case

    Create a sample case with evidence, a decision and an attachment.

  2. Export

    Request the case history and supporting records.

  3. Independent reading

    Open the export outside the product. Check whether the reasons, dates and evidence remain understandable.

Test the exported record outside the software

Read this visual with the source conditions and explanation in this section.

Follow the process from top to bottom.

Compare the full operating cost

Request a price for the same sample workload from each supplier. Separate licence fees from checks, additional users, setup, support and exit assistance. Ask what happens to read access and exports when the contract ends. Record any promise that is not included in the written offer. Keep future product features separate from functions you have tested in the current release.

Hypothetical example: an incomplete customer file

A practice tests a fictional customer whose information is incomplete. The product creates a task, but the demonstration cannot show who receives it. The practice records an unresolved requirement and asks for a second demonstration with an assigned reviewer. It does not treat the presence of a task feature as proof that its staff can operate the process. The same test can be used when comparing products without publishing a vendor ranking.

Sources and scope

Sources checked on 2026-09-06. This page is not continuously updated. Check the linked legislation and AUSTRAC guidance for current requirements.

  • Guidance for engaging a RegTech

    AUSTRAC · One-page PDF D1009, hosted under 2020-08; still linked from current RegTechs page checked 6 September 2026

  • Expectations of RegTechs

    AUSTRAC · One-page PDF D1008, hosted under 2020-08; still linked from current RegTechs page checked 6 September 2026

This page does not cover: Vendor rankings and recommendations; Detailed legal advice on contracts, privacy or liability; Independent evaluation and statutory CDD reliance requirements.

Common AML/CTF terms