The AUSTRAC audit process involves three supervisory pathways: desk-based reviews, on-site examinations and industry-wide programs. Selection is intelligence-led rather than random. AUSTRAC assesses whether an AML/CTF program was applied in practice, not merely documented.
Table of Contents
AUSTRAC Audit Process: What Happens and When
The AUSTRAC audit process is one of the highest-anxiety topics for professional services firms entering the AML/CTF regime, largely because so little is said about it. AUSTRAC conducts three types of supervisory activity: desk-based reviews, on-site examinations and industry-wide programs. Knowing which is which, and what each asks for, removes most of the uncertainty.
AUSTRAC conducts three types of supervisory activity: desk-based reviews, on-site examinations, and industry-wide supervisory programs. Each has different triggers, timelines, and preparation requirements. Knowing which type of review you are facing, and what evidence standard applies, is the first step in managing the process.
Key Takeaways
AUSTRAC Audit Process: How Firms Are Selected
AUSTRAC uses intelligence-led targeting to prioritise its supervisory activity. The selection criteria include: whether a reporting entity has registered on time; the nature and volume of the designated services it provides; intelligence from suspicious matter reports, law enforcement referrals, and financial intelligence analysis; complaints from other reporting entities or members of the public; and whether the entity’s transaction patterns deviate from sector norms.
For newly designated Tranche 2 entities, AUSTRAC’s initial supervisory focus is expected to target registration compliance, the existence of a Part A and Part B program, and basic KYC file quality. Firms that have not registered, or that registered with an obviously inadequate program, are at highest risk of early supervisory attention.
AUSTRAC also conducts periodic industry-wide supervisory programs that examine all entities in a sector, not just those with identified risk indicators. All professional services firms should plan for supervisory contact within their first two to three years of registration.
The Three Supervision Pathways
Desk-Based Review
A desk-based review is the most common form of initial supervisory contact. AUSTRAC notifies the entity in writing, requests specific documentation, and reviews that documentation without conducting an on-site examination. The documentation typically requested includes the firm’s AML/CTF program (Part A and Part B), risk assessment, staff training records, a sample of KYC files, transaction monitoring records, and suspicious matter and threshold transaction reporting records.
A desk-based review generally gives the entity 10 to 20 business days to provide the requested documentation. Responses should be thorough and well-organised. Gaps in documentation (missing training records, incomplete KYC files, or a program that has not been updated since initial adoption) will trigger further scrutiny.
On-Site Examination
An on-site examination involves AUSTRAC officers attending the firm’s premises to conduct interviews and inspect records directly. On-site examinations are used where a desk-based review has identified potential compliance concerns, where the firm operates high-risk designated services, or as part of an industry-wide supervisory program.
During an on-site examination, AUSTRAC officers may interview the Compliance Officer and other staff involved in providing designated services. They will test whether staff understand the firm’s AML/CTF procedures, whether KYC files are consistent with stated procedures, and whether transaction monitoring is operating as documented. The emphasis is on operational reality. What the firm actually does, not what its program document says it does.
Industry-Wide Supervisory Programs
Industry-wide supervisory programs examine a cross-section of entities in a sector simultaneously. AUSTRAC has used this approach in the real estate, gambling, and financial services sectors. For professional services, an industry-wide program is likely to follow the initial Tranche 2 commencement period, once AUSTRAC has gathered sufficient intelligence about sector-wide compliance patterns.
What AUSTRAC Actually Asks For
hether the review is desk-based or on-site, the evidence standard is consistent. AUSTRAC examines the following documentation categories:
- AML/CTF program, Part A (business-wide risk management) and Part B (customer identification and verification), including version history and evidence of senior management approval
- Risk assessment, the current ML/TF risk assessment and evidence that it has been reviewed and updated when circumstances change
- KYC files, a sample of customer identification and verification files, tested against the firm’s stated procedures
- Transaction monitoring records. Evidence that the monitoring system is operating and that alerts are being escalated and assessed
- Staff training records, a register of who received training, when, and what it covered, including induction and refresher training
- Reporting records. Evidence of suspicious matter report lodgements and threshold transaction reports where applicable
- Compliance Officer documentation: evidence of the role, responsibilities, and oversight activity of the designated Compliance Officer
The Evidence Standard: Practice, Not Paperwork
AUSTRAC’s enforcement history makes one pattern clear: the agency is not satisfied by a well-drafted program document sitting in isolation from the firm’s actual operations. The evidence standard is practice, not paperwork.
In the Commonwealth Bank enforcement action, the bank had formal AML/CTF procedures. The deficiency was that those procedures were not consistently followed in practice, and the monitoring systems did not operate as documented. In the Westpac action, the failures included transaction monitoring that was technically present but did not function correctly, and KYC procedures that did not capture the beneficial ownership information required by the rules.
For professional services firms, this means that KYC files must be complete and consistent across the client base. Training records must reflect actual training delivered to actual staff. The Compliance Officer must have evidence of regular oversight activity, not just a title on an organisational chart.
AUSTRAC interviewers are trained to identify the gap between what a program document says and what staff actually do. Firms that have adopted a compliant program but have not embedded it operationally are as vulnerable as firms that have no program at all.
Typical Deficiencies Found in Professional Services Firms
Based on AUSTRAC’s published enforcement actions and supervisory findings from analogous overseas regimes, the most common deficiencies in professional services sector firms are:
- Programs adopted at commencement but never updated after regulatory changes or changes in the firm’s services or client base
- KYC files that are incomplete, rely on expired documents, or do not capture beneficial ownership for corporate and trust clients
- No evidence of staff training, or training that is undocumented
- Transaction monitoring that is manual, undocumented, and inconsistently applied
- No records of the Compliance Officer’s oversight and review activity
- Suspicious matter report processes that are known to the Compliance Officer but not documented or communicated to all relevant staff
Enforceable Undertakings and Civil Penalties
Where AUSTRAC’s supervisory review identifies material compliance failures, it will assess the appropriate enforcement response. The graduated approach moves from remediation-focused engagement to enforceable undertakings to civil penalty proceedings, depending on the seriousness of the failures and the firm’s response.
An enforceable undertaking requires the firm to commit to specific remediation steps: typically independent audit, program remediation, enhanced reporting to AUSTRAC, and board-level oversight. Enforceable undertakings are publicly disclosed. For a professional services firm, public disclosure of an enforceable undertaking constitutes a significant reputational consequence in addition to the remediation cost.
How DBA Advisory Prepares Firms for AUSTRAC Scrutiny
DBA Advisory’s AML/CTF program build service is designed to produce programs that meet AUSTRAC’s evidence standard from day one. This means drafting a compliant program document but ensuring that KYC procedures are operationally embedded, training is delivered and documented, and the Compliance Officer function is active and evidenced. For firms approaching a supervisory review, DBA Advisory offers a pre-review audit service that assesses your program against AUSTRAC’s evidence standard and identifies gaps before the reviewer does.
AUSTRAC audit processa: what your files have to show
The part firms do not prepare for is the interview. Reviewers ask the people who actually onboard clients what they do, in their own words, and compare the answers to the program document. A well-written program described differently by three staff members is a finding on its own, and no amount of drafting fixes it after the fact.
Selection is risk-based rather than random, and supervision runs through desk-based review, on-site examination, and industry-wide programs. Across all three the evidence standard is the same: practice, not paperwork. The deficiencies found most often in professional firms are programs never updated after a regulatory change, and client files that are missing the reason behind the risk rating.
Frequently Asked Questions (FAQs)
AUSTRAC uses intelligence-led targeting. Factors include registration compliance, the nature and volume of designated services, suspicious matter report patterns, and financial intelligence from law enforcement referrals. Newly designated Tranche 2 entities should expect supervisory contact within their first two to three years of registration. AUSTRAC also conducts periodic industry-wide supervisory programs that apply to all entities in a sector.
For desk-based reviews, AUSTRAC typically provides written notice and allows 10 to 20 business days to respond with documentation. On-site examinations may be preceded by shorter notice periods. AUSTRAC has power to conduct unannounced on-site examinations in certain circumstances, though this is less common in the supervisory context and more typical in formal investigations.
AUSTRAC will typically request your AML/CTF program (Part A and Part B), current risk assessment, a sample of KYC files, transaction monitoring records, staff training records, and suspicious matter and threshold transaction reporting records. The emphasis is on evidence that your program is operating in practice, not just on paper.
If AUSTRAC finds no material compliance concerns, it will close the review and may provide feedback on areas for improvement. Where material failures are identified, AUSTRAC will engage with the entity on remediation and may issue an enforceable undertaking or, for serious failures, commence civil penalty proceedings. Enforceable undertakings are publicly disclosed on AUSTRAC's website.
AUSTRAC has powers under the AML/CTF Act to enter premises and inspect records without prior notice in certain circumstances. These powers are most commonly exercised in formal investigation contexts rather than routine supervisory reviews. The majority of Tranche 2 professional services firm reviews will begin with written notification and a documentation request.
How DBA Advisory Supports You
DBA Advisory offers fixed-fee AML/CTF pre-review audit and program remediation services engagements with no hidden costs. Contact our team at dbaadvisory.com to discuss your requirements. General information only, not legal, tax, or compliance advice. Verify all obligations against current AUSTRAC, ATO, and legislative guidance.
How DBA AML Supports You
This work is delivered by DBA AML Group Pty Ltd, the specialist AML/CTF compliance entity within DBA Advisory. It is a service rather than software: real AML/CTF practitioners do the work, so what leaves your desk is the function itself, not a portal to configure and operate. You remain the reporting entity; the operations move.
DBA AML Group Pty Ltd · ACN 697 643 404 · hello@dbaaml.com · dbaaml.com · We respond within one business day. Scope and fees are confirmed after a discovery call.
Would your client files survive a desk review? The KYC/CDD Client File Checklist shows what a defensible CDD file contains, including the ten-minute file audit reviewers effectively run on you. Download it free or book a meeting today!
Disclaimer
© DBA Advisory 2026. This article is intended as general information only and does not constitute legal or compliance advice. Businesses should seek qualified advice specific to their circumstances before acting on any information contained in this article.
Related Insights
We build the resilient foundations
empowering you
to scale your business
Get in touch
Alquin Dagamina
Business Transformation and Technology Services, Manager
- Alquin.Dagamina@dbaadvisory.com
- 09158918379

