Knowing that your business has anti-money laundering obligations is one thing. Turning those obligations into a working AML/CTF program is another.
For Australian reporting entities, an AML/CTF program is not supposed to be a generic compliance document that sits untouched in a folder. It needs to reflect the actual money laundering, terrorism financing and proliferation financing risks the business may face and explain how those risks will be managed in practice.
That has become even more important under Australia's reformed AML/CTF regime. The framework is now more explicitly risk-based and outcomes-focused, which means businesses need to understand their own exposure rather than simply work through a standard compliance template.
If you need the broader regulatory picture first, our guide to anti-money laundering in Australia explains how reporting entities, designated services, AUSTRAC and the wider AML/CTF framework fit together.
In this guide, we'll focus specifically on the AML/CTF program itself: what it includes, who needs one, how to build it and what businesses need to do to keep it effective.
What Is an AML/CTF Program?
An AML/CTF program is the framework a reporting entity uses to identify, assess, manage and mitigate the money laundering, terrorism financing and proliferation financing risks associated with its designated services.

Under AUSTRAC's current AML/CTF program guidance, the program has two core elements:
- an ML/TF risk assessment; and
- AML/CTF policies.
The risk assessment identifies the ML/TF risks the business may reasonably face. The AML/CTF policies then set out the policies, procedures, systems and controls the business will use to manage those risks and comply with its obligations.
In simple terms, the risk assessment answers:
Where could our business be exposed to ML/TF risk?
The policies answer:
What are we going to do about those risks?
Those policies can then affect areas such as customer due diligence, transaction monitoring, internal escalation, staff responsibilities, reporting, record keeping and ongoing review.
An AML/CTF program therefore needs to be connected to how the business actually operates. A document that describes controls which employees do not understand or follow is unlikely to achieve what the program is supposed to do.
Who Needs an AML/CTF Program in Australia?
The key question is generally whether a business provides a designated service under Australia's AML/CTF regime.
Businesses that provide designated services and fall within the definition of a reporting entity can have obligations to develop, maintain and comply with an AML/CTF program.
That includes established regulated sectors such as financial services as well as businesses brought within the expanded regime through Australia's recent AML/CTF reforms.
Since 1 July 2026, certain designated services provided by sectors including real estate, legal, conveyancing, accounting, trust and company services, and dealers in precious metals or stones have become subject to the expanded AML/CTF framework.
However, regulation does not simply depend on someone's profession or job title. What matters is whether the business is providing a designated service covered by the legislation.
Our guide to Tranche 2 AML requirements in Australia explains the newly regulated sectors and designated-service concept in more detail.
An AML/CTF program also sits within a wider compliance framework. Reporting entities may have responsibilities relating to customer due diligence, AUSTRAC reporting, record keeping, personnel and other controls. Our guide to AML/CTF compliance obligations explains how those requirements fit together.
What Must an AML/CTF Program Include?
At its core, an AML/CTF program needs to include the organisation's ML/TF risk assessment and AML/CTF policies.
Those two elements should not operate in isolation.
The risk assessment should inform the policies, and the policies should establish the practical procedures, systems and controls used to manage the risks identified.
A functioning AML/CTF framework will generally need to address areas including:
- governance and responsibility;
- ML/TF risk assessment;
- customer due diligence;
- ongoing customer monitoring;
- personnel due diligence and training;
- internal escalation and reporting;
- record keeping;
- review and updating; and
- independent evaluation.
That does not mean these are separate statutory “pillars” that every organisation implements identically.
Australia's framework is risk-based. The controls used by a small accounting practice may therefore look very different from those used by a large financial institution, even though both operate within the same broader regulatory framework.
How to Build an AML/CTF Program
Building the program starts with understanding who is responsible and what risks the business actually faces.
Step 1: Establish Governance and Responsibility
An AML/CTF program needs clear ownership.
Under the current framework, businesses need to identify relevant governance roles, including:
- the governing body responsible for oversight;
- an AML/CTF compliance officer responsible for coordinating day-to-day compliance; and
- a senior manager or relevant senior managers responsible for approving the program and making required decisions.
The exact structure will depend on the nature and size of the organisation. A large reporting entity may have dedicated compliance teams, while a small business may have one person performing several responsibilities.
What matters is that accountability is clear.
The business should know who is responsible for maintaining the program, who receives compliance information, who approves changes and where significant issues are escalated.
Governance should not end once the initial document has been approved. Senior personnel and the governing body need enough information to understand whether the program continues to manage the organisation's risks effectively.
Step 2: Conduct an ML/TF Risk Assessment
The risk assessment is the foundation of the AML/CTF program.
A reporting entity needs to identify and assess the money laundering, terrorism financing and proliferation financing risks it may reasonably face when providing its designated services.
Relevant factors can include:
- the types of customers the business deals with;
- the designated services it provides;
- how those services are delivered;
- jurisdictions connected with customers, transactions or funds;
- technology used in delivering services; and
- emerging or changing financial crime risks.
For example, a business dealing only with relatively straightforward domestic customers may face a different risk profile from one handling complex corporate structures, high-value transactions or customers connected to higher-risk jurisdictions.
The aim is not to treat every customer or transaction as suspicious.
The purpose is to identify where greater risk exists, so the organisation can apply controls that are proportionate to that risk.
It is also important to distinguish the organisation's business-wide ML/TF risk assessment from an individual customer's risk rating. The first considers the risks the business may face across its designated services. Customer risk assessment then applies that wider framework to particular customer relationships.

Step 3: Develop AML/CTF Policies, Procedures and Controls
Once the risks have been identified, the business needs to decide how it will manage them.
This is where the AML/CTF policies come in.
Policies should explain the procedures, systems and controls used to manage identified risks and meet regulatory obligations.
Depending on the business, that could include procedures covering:
- customer onboarding;
- identity verification;
- beneficial ownership;
- customer risk assessment;
- enhanced due diligence;
- transaction monitoring;
- suspicious activity escalation;
- record keeping;
- personnel responsibilities; and
- regulatory reporting.
A useful way to think about this is:
Risk → policy → procedure → control → evidence.
If the risk assessment identifies a particular vulnerability, there should be a logical connection between that vulnerability and the controls used to address it.
This is one reason businesses should be cautious about downloading a generic AML template and treating the work as finished. A template may help provide structure, but the final program still needs to reflect the reporting entity's own designated services, customers and risks.
Step 4: Build Customer Due Diligence Into the Program
Customer due diligence, or CDD, is a major operational part of AML/CTF compliance.
Reporting entities need processes for establishing who their customers are, verifying relevant information and assessing the risks associated with the relationship.
Depending on the circumstances, CDD may involve:
- identifying and verifying customers;
- identifying beneficial owners;
- assessing customer risk;
- identifying politically exposed persons;
- understanding relevant source-of-funds or source-of-wealth information; and
- applying enhanced due diligence where greater risk exists.
CDD should not become a simple document-collection exercise.
The objective is to understand who the business is dealing with, what risk the relationship presents and whether the customer's activity makes sense in the circumstances.
A straightforward domestic customer may require different controls from a customer involving several overseas companies, complex ownership arrangements or unexplained funding sources.
Step 5: Establish Ongoing Monitoring and Escalation
Risk does not necessarily stay the same after onboarding.
Customer behaviour, ownership, transactions and other circumstances can change over time. Reporting entities therefore need processes for ongoing customer due diligence and monitoring.
That may include looking for:
- transactions inconsistent with expected activity;
- unusual payment arrangements;
- significant changes in customer behaviour;
- new information affecting the customer's risk rating; or
- circumstances requiring additional investigation or escalation.
When concerns arise, employees should know what happens next.
The program should make clear who receives an internal escalation, how it is assessed and when the matter may trigger an AUSTRAC reporting obligation.
Our guide to AUSTRAC reporting requirements for Australian reporting entities covers Suspicious Matter Reports and other reporting obligations in more detail.
Step 6: Train the People Who Apply the Program
A strong AML/CTF program depends on the people expected to use it.
Businesses need to identify personnel whose roles affect AML/CTF compliance and make sure they receive training appropriate to their responsibilities.
That could include:
- customer-facing employees;
- onboarding teams;
- compliance personnel;
- managers;
- people responsible for transactions or payments; and
- contractors or third parties performing relevant functions.
Training should be role-specific.
Someone onboarding customers may need detailed knowledge of identification, beneficial ownership and customer risk. A manager may instead need greater understanding of governance, oversight and escalation.
Our guide to AML training in Australia explains who should receive training, what it should cover and how businesses can manage training as an ongoing compliance process.
For organisations building staff knowledge, our Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) course provides practical training focused on Australian AML/CTF requirements.
Training does not replace an organisation's AML/CTF program. It helps the people responsible for applying that program understand the risks, procedures and responsibilities relevant to their work.
Step 7: Keep Records That Show What Actually Happened
AML/CTF compliance needs evidence.
Businesses should maintain appropriate records showing how their program and related obligations have been carried out.
Depending on the circumstances, that may include records relating to:
- customer identification and verification;
- customer and business risk assessments;
- transactions;
- compliance decisions;
- escalations;
- reports;
- staff training;
- program approvals and updates; and
- independent evaluations.
This distinction matters.
A policy saying that employees should complete a particular check is different from a record showing that the check was actually completed.
Good record keeping allows the business to demonstrate how its procedures operate in practice and provides information that can also support internal reviews and independent evaluations.
Step 8: Review, Update and Independently Evaluate the Program
An AML/CTF program should evolve with the business.
Changes to customers, services, technology, delivery channels or financial crime risks can make an existing risk assessment or control less effective.
AUSTRAC requires reporting entities to review and update their AML/CTF programs when relevant circumstances require it. The entire risk assessment and AML/CTF policies must also be reviewed at least once every three years.
Updates may be necessary following events such as:
- significant changes to the business;
- new or changed designated services;
- changes in customer or jurisdictional risk;
- new delivery methods or technologies;
- changes to regulation or AUSTRAC guidance; or
- weaknesses identified through reviews or independent evaluation.
An independent evaluation is separate from the business's own internal review process. Under current AUSTRAC guidance, one must occur at least once every three years, with the frequency appropriate to the nature, size and complexity of the organisation.
The evaluator may be internal or external, provided they are sufficiently independent and suitable for the work.

Do AML/CTF Programs Still Have Part A and Part B?
Older Australian AML resources often refer to Part A and Part B of an AML/CTF program.
That terminology reflects the previous regulatory structure.
Australia's reforms removed the prescriptive requirement to maintain separate Parts A and B. The current framework instead gives reporting entities greater flexibility to structure their program, provided it effectively identifies, assesses, manages and mitigates relevant risks and meets the organisation's AML/CTF obligations.
The Department of Home Affairs explains this shift in its guidance on changes to AML/CTF program requirements.
For businesses developing a program today, this means older templates should be treated carefully. A document built entirely around the previous Part A/Part B structure may not reflect the current requirements.
The focus now is much more clearly on whether the organisation has understood its risks and built effective controls around them.
Your AML/CTF Program Should Reflect Your Actual Business Risks
There is no single AML/CTF program that will work for every Australian business.
Consider a real estate agency, an accounting practice and a financial institution. All may operate under Australia's AML/CTF framework, but their customers, transaction patterns, delivery methods and risk exposure can be very different.
A real estate business, for example, may need to consider risks involving complex property ownership, third-party payments, overseas purchasers or unusual sources of funds.
Our guide to AML/CTF requirements for Australian real estate businesses explains how those obligations can apply specifically to agents, lawyers, conveyancers and accountants involved in property transactions.
The wider principle is the same across sectors: the program should be designed around the risks of the business rather than forcing the business into a generic program.

Common AML/CTF Program Mistakes to Avoid
Even a detailed written program can fail if it does not reflect how the organisation actually works.
Common problems can include:
- copying a generic template without tailoring it to the business;
- treating the ML/TF risk assessment as a one-off exercise;
- failing to connect identified risks with actual controls;
- leaving governance responsibilities unclear;
- treating CDD as nothing more than collecting identification;
- giving every employee identical AML training regardless of role;
- failing to document important decisions and actions;
- not updating policies when the business or its risks change; and
- relying on outdated Part A and Part B material.
The strongest AML/CTF programs create a clear connection between risk, responsibility, controls and evidence.
That makes the program useful in day-to-day operations rather than simply something the organisation holds for compliance purposes.
Final Takeaway
An effective AML/CTF program starts with understanding the risks a business actually faces.
The ML/TF risk assessment identifies those risks. The organisation's AML/CTF policies then translate that assessment into practical procedures, systems and controls covering areas such as CDD, monitoring, personnel, reporting, governance and record keeping.
But the work does not stop once the program has been written. Businesses need to follow it, test whether it remains effective and update it as their circumstances change.
And because employees are the people applying many of those controls in practice, appropriate training remains a core part of making the framework work. Our Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) course can help Australian teams build practical understanding of AML/CTF risks and responsibilities.
