A purchase is one part of the process
AUSTRAC’s program guidance covers a risk assessment, policies, approval, daily use, review and records. A software purchase is not evidence that these steps have occurred. Software can support the work. The relevant question is which part it supports and how the rest will be carried out. This also applies to the readiness tool on this site: using it does not confirm compliance.
- Product
A feature performs a defined task.
- People
Someone owns the next action.
- Procedure
The program explains how to act.
- Evidence
Records show what happened.
Connect the product to daily work
Suggested review structure. Completing these steps does not confirm compliance.
Follow the process from top to bottom.
Suggested responsibility check
For each procedure, write down who supplies the information, who performs the check and who acts on an unresolved result. A supplier may perform some of that work under an agreed service. Confirm the allocation instead of assuming that the software company handles every task visible on its screen. Use the service-provider guide when the purchase also includes people who perform work for you.
Connect a result to an action
Imagine that a system marks a customer for further review. Ask where the case goes next, how the reviewer receives it and what happens while it is unresolved. Then test the process with fictional information. This exercise helps identify an unassigned task. It does not prescribe a customer decision, a reporting threshold or permission to continue providing a service.
Keep evidence beyond the invoice
An invoice shows that you paid for a product. Suggested implementation evidence could include an approved procedure, a record of staff practice and a completed test case. Keep the reason for any change made during setup. These examples help distinguish a purchase record from evidence of work performed. They are not an exhaustive list of required AML records.
Allow for changes after setup
AUSTRAC says programs must be reviewed and updated as circumstances change. A supplier may provide product updates, but the business still needs to understand their effect on its process. Ask who receives change notices and who checks the affected procedure.
Hypothetical example: screening without a reviewer
A fictional firm enables screening and assumes the setup is complete. During a staff exercise, a possible match enters a queue that nobody checks. The firm assigns responsibility, agrees an escalation process and repeats the exercise. The example shows why a working feature needs an operating process. It does not decide whether a match is correct or whether a report is required.