Australian AML/CTF · Explainer

What does a senior manager approve in the AML program?

Tie approval to the actual risk assessment, policies and changed versions.

General information only, not legal, compliance, or other professional advice. Does not confirm compliance.

Start with: Does AML regulation follow your service or your profession?

Approve an identifiable document

Approval should identify what was approved. AUSTRAC explains that a senior manager must approve the risk assessment, AML/CTF policies and updates. It also distinguishes these personal decision duties from oversight functions. A message saying AML approved is hard to use if several drafts existed. Connect the approval to the specific documents and version. The record should let another person establish which instructions staff were authorised to use, rather than infer that from the newest file in a shared folder.

Prepare a useful decision pack

A suggested approval pack contains the proposed document, a brief explanation of material changes and any unresolved implementation issue. Explain why a control changed and what staff will need to do differently. If a new procedure depends on a system or supplier, show whether that dependency is ready. This helps the manager decide on a concrete proposal. It also avoids treating an unread attachment as meaningful evidence that the business considered how the revised program would operate.

An approval needs a usable versionFollow the process from top to bottom. Proposed change: Show the document version and what will change. Manager decision: Record approval of the risk assessment and policies under the applicable requirements. Staff instruction: Give staff the approved version and identify when it takes effect.Proposed change Manager decision Staff instruction
  1. Proposed change

    Show the document version and what will change.

  2. Manager decision

    Record approval of the risk assessment and policies under the applicable requirements.

  3. Staff instruction

    Give staff the approved version and identify when it takes effect.

An approval needs a usable version

Read this visual with the source conditions and explanation in this section.

Follow the process from top to bottom.

Example: a changed intake process

Imagine a revised policy introduces a new escalation route for uncertain customer information. The approval pack identifies the changed section, the reason for the change and the team responsible. After approval, the business publishes the approved version and updates the relevant staff instructions. A useful follow-up checks whether staff use the new route. This example separates the approval decision from implementation and testing. An approval record can show authorisation without proving that the new process was followed on every file.

Connect approval and release

Use a controlled process to move a document from draft to approved to in use. Suggested records include the approver, date, version and effective operational instruction. Keep superseded versions available under the applicable retention requirements. Section 26P requires written notice of any risk assessment update to the governing body as soon as practicable after the update. Give staff one clear place to obtain current instructions. When correcting an error, preserve the record of the earlier decision rather than editing the old approval to look as if it covered the new text.

Handle conditional decisions

If a proposed change cannot yet operate, record the outstanding dependency and the manager’s actual decision. Do not describe a draft proposal as an operational approval. Make any later approval identifiable. This helps staff distinguish planning progress from the instructions they are currently authorised and equipped to use in customer work.

Sources and scope

Sources checked on 2026-09-06. This page is not continuously updated. Check the linked legislation and AUSTRAC guidance for current requirements.

This page does not cover: Every statutory variation or exemption affecting approval.

Common AML/CTF terms