Different questions need different checks
Your own review and an independent evaluation serve related but different purposes. The Act separately addresses risk assessment and policy review and independent evaluation. AUSTRAC’s program guide explains that the business needs to determine evaluator independence and suitability and obtain written findings. An internal maintenance check should not simply be labelled independent. Internal review helps keep the program current; evaluation examines it with the relevant independence. The applicable duties depend on the entity and service circumstances, including the Australian-establishment condition in section 26F.
- AML/CTF program quick guide: Page 5: Review and update your AML/CTF program; Conduct an independent evaluation
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006: Sections 26D and 26F(2) to (4)
- Define review
Identify the work and independence needed.
- Examine evidence
Use suitable tests and explain sample limits.
- Report findings
Provide the written result to relevant roles.
- Address issues
Assign actions and check their effect.
From evaluation to verified action
Suggested action flow based on the guidance; it does not set evaluation deadlines.
Follow the process from top to bottom.
Specify a useful evaluation
A suggested evaluation brief identifies the services, procedures, period and evidence to be examined. Ask how the evaluator will select files and explain their findings. Make access arrangements before work starts, including the handling of sensitive records. Avoid a brief that asks only whether a policy document exists. A policy can be present while its steps are not followed. The report is more useful when it connects the evidence tested with the conclusions reached and describes important limits in the sample.
Example: a process that exists only on paper
Suppose a policy requires an escalation step, but sampled files do not show whether staff used it. An internal review can investigate the immediate gap and repair instructions. An independent evaluator may consider whether the issue reveals a broader weakness in design or practice. Neither conclusion should exceed the evidence examined. This example shows why checking a document and checking its operation are different tasks. It also shows why a favourable sample does not establish that every customer file is correct.
Turn findings into decisions
Give each material finding an owner, proposed response and completion evidence. Explain any decision not to adopt a recommendation rather than silently dropping it. Provide the written report to the relevant governance roles as required, then track whether the response works. If you change the risk assessment or policies, use the appropriate approval process. Check current requirements for evaluation frequency and triggers separately. A completed evaluation is useful evidence about the work examined; it is not a permanent certificate that the business complies in all circumstances.
Preserve the scope of assurance
When sharing an evaluation result, include the period, activities and evidence examined. Avoid reducing a qualified finding to a simple pass. If parts of the business were not reviewed, keep that limit visible. Future decisions can then use the report appropriately rather than assuming it covers work the evaluator never tested.