AML/CTF training requirements apply to all staff involved in providing designated services, including support staff who handle customer information. Training must cover obligations, red flags and internal reporting, and must be documented in a way that evidences understanding rather than attendance alone.
Table of Contents
AML/CTF Training Requirements:
Who Needs It and How to Document It
AML/CTF training requirements reach further into a firm than most people assume. It is not only the client-facing staff. Anyone involved in providing designated services, including administrative staff who handle customer information, falls within scope. The harder question is not who, but how you evidence that they actually understood it. Confirm current requirements against AUSTRAC guidance.
For professional services firms that have become reporting entities under the Tranche 2 expansion, the training obligation applies from the date of AUSTRAC registration. This guide explains who must be trained, what training must cover, how frequently it must be refreshed, and how to document it.
Key Takeaways
Who AML/CTF Training Requirements Actually Apply To
AUSTRAC’s rules require training for all employees, contractors, and agents involved in providing designated services. The obligation is not limited to the AML/CTF Compliance Officer or senior management. It extends to any person who has contact with customers in the context of providing a designated service, who processes transactions, who handles customer documentation, or who has responsibility for any part of the AML/CTF compliance process.
In a legal or accounting firm, this typically includes: partners and principals; employed solicitors, accountants, and paralegals; reception and administrative staff who handle client onboarding; trust account clerks; and any contractors engaged to provide designated services on the firm’s behalf.
What Training Must Cover
AUSTRAC’s rules specify that AML/CTF training must include:
- The obligations of the reporting entity under the AML/CTF Act and the entity’s AML/CTF program
- How to recognise transactions or behaviour that may be suspicious
- How to handle a suspicious matter, including the requirement to escalate internally and the prohibition on tipping off the customer
- The entity’s internal reporting and escalation procedures
- The record-keeping obligations associated with customer identification and transactions
Training should be tailored to the role of the person being trained. A client-facing solicitor managing property settlements needs different training content from an administrative officer who processes incoming wire transfers. The core obligations are the same, but the practical application differs.
Training Documentation Requirements
AUSTRAC does not prescribe a specific format for training records, but requires that records be sufficient to demonstrate compliance. Best practice documentation includes: a training register recording the name of each person trained, their role, the date of training, the content covered, and the delivery method; copies of training materials used; records of any assessment or acknowledgement by trainees; and records of refresher training cycles.
Training records must be retained for at least seven years. They should be stored in a way that allows them to be retrieved and produced to AUSTRAC promptly in a supervisory review.
Refresher Training and Program Updates
AUSTRAC requires that training be provided when an employee commences in a role involving designated services, and when the AML/CTF program or the relevant regulations are updated in a material way. Best practice is to provide annual refresher training for all staff, timed to the annual program review cycle. When new regulatory guidance is issued or when AUSTRAC publishes updated typologies for the professional services sector, a targeted training update should be provided.
Building a training calendar that runs itself
The training obligation fails quietly: everyone is trained at launch, then hiring happens, roles change, a year passes, and the training record describes a team that no longer exists. The fix is structural, not motivational, a standing calendar with three entries.
First, onboarding training wired into the induction checklist, so no one touches client onboarding before completing it. Second, annual refresher training for everyone in scope, booked as a recurring event rather than an intention. Third, event-driven updates whenever the program materially changes: a new service line, a new escalation path, a regulatory shift. Each session leaves a record: who, when, what was covered, and any assessment outcome.
Keep the register beside the program document, not in someone’s inbox. When a reviewer asks ‘show me your training records’, the answer should be one attachment. And the firms that can produce it in one attachment are almost always the firms whose training actually happened.
AML/CTF training requirements:
Evidencing competence, not attendance
DBA Advisory builds role-based training programs with the documentation that proves they happened, including the register reviewers ask for.
Undocumented training is indistinguishable from no training. A firm that trains its people well in an informal conversation, and records nothing, presents exactly the same evidence to a reviewer as a firm that never bothered. The register, the attendance record and ideally a short competence check are what turn the effort into something that counts.
Everyone involved in providing designated services needs training, new staff before they start on that work, and existing staff on a refresher cycle and whenever the program changes. Content has to cover the obligations, your own procedures, how to recognise and escalate suspicious matters, and the consequences of getting it wrong. Role-based content beats one deck for the whole firm.
How DBA Advisory Supports You
DBA Advisory offers fixed-fee AML/CTF program build, staff training design, and compliance documentation engagements with no hidden costs. Contact our team to discuss your requirements. Verify all obligations against current AUSTRAC, ATO, and legislative guidance.
Keep the training record with the program itself rather than in somebody’s inbox. A reviewer will ask for it, and the firms that produce it in minutes are the ones treating training as part of the program instead of an annual chore.
Not sure where your firm stands under Tranche 2? The AML/CTF Compliance Readiness Assessment is a scored, plain-English self-assessment you can complete in fifteen minutes. Download it free or book a meeting today!
How DBA AML Supports You
This work is delivered by DBA AML Group Pty Ltd, the specialist AML/CTF compliance entity within DBA Advisory. It is a service rather than software: real AML/CTF practitioners do the work, so what leaves your desk is the function itself, not a portal to configure and operate. You remain the reporting entity; the operations move.
DBA AML Group Pty Ltd · ACN 697 643 404 · hello@dbaaml.com · dbaaml.com · We respond within one business day. Scope and fees are confirmed after a discovery call.
Frequently Asked Questions (FAQs)
All staff, contractors, and agents involved in providing designated services must receive AML/CTF training. This includes client-facing staff, trust account clerks, administrative officers involved in customer onboarding, and any contractors providing designated services on the firm's behalf. The Compliance Officer must also maintain their own training and awareness of regulatory developments.
AUSTRAC requires training at commencement and on material updates to the program or regulations. Best practice is annual refresher training for all staff. Targeted training updates should also be provided when AUSTRAC issues new guidance, when the firm's designated services change, or when a compliance failure or near-miss identifies a training gap.
Records must document who received training, when, and what it covered. This typically means a training register, copies of training materials, and records of any acknowledgement or assessment. Records must be retained for seven years and must be available for production to AUSTRAC in a supervisory review. The absence of training records is one of the most common deficiencies AUSTRAC identifies in professional services firm reviews.
Disclaimer
© DBA Advisory 2026. This article is intended as general information only and does not constitute legal or compliance advice. Businesses should seek qualified advice specific to their circumstances and confirm all regulatory references against current guidance before acting on any information contained in this article.
Related Insights
We build the resilient foundations
empowering you
to scale your business
Get in touch
Alquin Dagamina
Business Transformation and Technology Services, Manager
- Alquin.Dagamina@dbaadvisory.com
- 09158918379

