Australian AML/CTF · Explainer

Why buying AML software is not enough

Software can support AML work. Your business still needs an approved program, assigned responsibilities and evidence that its procedures are used.

General information only, not legal, compliance, or other professional advice. Does not confirm compliance.

Start with: When does an AML program become a working process?

A purchase is one part of the process

AUSTRAC’s program guidance covers a risk assessment, policies, approval, daily use, review and records. A software purchase is not evidence that these steps have occurred. Software can support the work. The relevant question is which part it supports and how the rest will be carried out. This also applies to the readiness tool on this site: using it does not confirm compliance.

Connect the product to daily workFollow the process from top to bottom. Product: A feature performs a defined task. People: Someone owns the next action. Procedure: The program explains how to act. Evidence: Records show what happened.Product People Procedure Evidence
  1. Product

    A feature performs a defined task.

  2. People

    Someone owns the next action.

  3. Procedure

    The program explains how to act.

  4. Evidence

    Records show what happened.

Connect the product to daily work

Suggested review structure. Completing these steps does not confirm compliance.

Follow the process from top to bottom.

Suggested responsibility check

For each procedure, write down who supplies the information, who performs the check and who acts on an unresolved result. A supplier may perform some of that work under an agreed service. Confirm the allocation instead of assuming that the software company handles every task visible on its screen. Use the service-provider guide when the purchase also includes people who perform work for you.

Connect a result to an action

Imagine that a system marks a customer for further review. Ask where the case goes next, how the reviewer receives it and what happens while it is unresolved. Then test the process with fictional information. This exercise helps identify an unassigned task. It does not prescribe a customer decision, a reporting threshold or permission to continue providing a service.

Keep evidence beyond the invoice

An invoice shows that you paid for a product. Suggested implementation evidence could include an approved procedure, a record of staff practice and a completed test case. Keep the reason for any change made during setup. These examples help distinguish a purchase record from evidence of work performed. They are not an exhaustive list of required AML records.

Allow for changes after setup

AUSTRAC says programs must be reviewed and updated as circumstances change. A supplier may provide product updates, but the business still needs to understand their effect on its process. Ask who receives change notices and who checks the affected procedure.

Hypothetical example: screening without a reviewer

A fictional firm enables screening and assumes the setup is complete. During a staff exercise, a possible match enters a queue that nobody checks. The firm assigns responsibility, agrees an escalation process and repeats the exercise. The example shows why a working feature needs an operating process. It does not decide whether a match is correct or whether a report is required.

Sources and scope

Sources checked on 2026-09-06. This page is not continuously updated. Check the linked legislation and AUSTRAC guidance for current requirements.

This page does not cover: Vendor rankings and recommendations; Detailed legal advice on contracts, privacy or liability; Independent evaluation and statutory CDD reliance requirements.

Common AML/CTF terms