How to Build an AML/CTF Compliance Program

An AML/CTF compliance program is not a policy document you file and forget. Every accountant, lawyer and professional services firm that becomes a reporting entity must adopt a written program, apply it in practice, and be able to show the evidence.

Table of Contents

Build an AML/CTF Compliance Program in 60 Days

Every accountant, lawyer, and professional services firm that becomes a reporting entity under Australia’s Anti-Money Laundering and Counter-Terrorism Financing Act from 1 July 2026 faces the same question: where do we actually start? AUSTRAC does not hand you a template. It does not publish a step-by-step guide. What it publishes is a set of obligations: and the task of converting those obligations into a functioning AML/CTF compliance program Australia firms can actually operate falls entirely to you.

This guide walks you through building a compliant AML/CTF program from a blank page. The timeline is 60 days. Firms that work methodically through the stages below will have a defensible, operational program before AUSTRAC supervisory activity begins in earnest.

Key Takeaways

an image of a forest in autumn with different colored leaves on trrees, symbolising the changes in Australia with the AML/CTF Compliance Program requirements

What an AML/CTF Compliance Program Australia Requires Must Contain

The AML/CTF Act requires every reporting entity to adopt and maintain a written AML/CTF program. Under AUSTRAC’s rules, Part A of the program governs how the entity manages money laundering and terrorism financing risk across the business. Part B governs customer identification and verification, your KYC procedures.

A compliant program is not a document that describes policy. It is a document that describes practice, how the business actually identifies customers, how it assesses risk, how staff are trained, and how it responds when something unusual occurs. AUSTRAC’s enforcement history shows that firms are penalised not for having an imperfect program but for having a program that does not reflect what happens on the ground.

Week 1 to 2: Conduct Your ML/TF Risk Assessment

Before you write a single policy, you need to understand your firm’s exposure. The AML/CTF Act requires a business-wide risk assessment that examines the nature of the services you provide, the customers who use them, the delivery channels through which services are provided, and the jurisdictions involved.

For an accounting or legal firm, the risk assessment must address: which designated services you provide and to which client segments; which of your clients are higher-risk by ownership structure, business type, or jurisdiction; whether you accept cash or deal with high-volume transactions; and whether any clients are politically exposed persons or have connections to sanctioned jurisdictions.

Document your findings in a risk assessment report that can be provided to AUSTRAC on request. The risk assessment is the foundation of your program. Every procedure that follows should be proportionate to the risks you have identified here.

AUSTRAC's supervisory approach examines whether your program reflects a genuine understanding of your firm's risk exposure. A generic template that does not address your specific services and client base will not satisfy a supervisory review.

an image of a mountain side covered in clouds during sunrise, symbolising the benefits if DBA Advisory's AML/CTF Compliance Program for Australian businesses

Week 3 to 4: Draft Your Program Document

With your risk assessment complete, you can draft Part A and Part B of your AML/CTF program. Part A must include the appointment of an AML/CTF Compliance Officer, a governance framework for oversight and accountability, your ML/TF risk assessment and how it will be maintained, your transaction monitoring approach, ongoing customer due diligence procedures, and your reporting obligations for suspicious matter reports, threshold transaction reports, and international funds transfer instructions.

Part B must include your customer identification procedures by customer type, enhanced due diligence procedures for higher-risk customers, beneficial ownership verification requirements, and how you will handle customers you cannot identify.

Both parts must be reviewed and approved by senior management. AUSTRAC expects the Compliance Officer and firm leadership to be personally accountable for the program.

Week 5 to 6: Build Your KYC and CDD Procedures

Customer due diligence is where most firms spend the most time. And where most compliance failures are found. Your KYC procedures must specify: what identification documents you accept for each customer type; how you verify identity for individual clients, companies, trusts, and partnerships; and what enhanced due diligence looks like for higher-risk customers.

For individual clients, AUSTRAC’s customer identification procedures require collecting full legal name, date of birth, and residential address, then verifying at least two of those elements against independent sources. For corporate clients, you need to verify the company’s legal name, registration number, and registered address, and identify any beneficial owners who hold 25 per cent or more of the entity.

For professional services firms, the trust and partnership client types deserve particular attention. These are high-risk structures commonly used to obscure beneficial ownership, and AUSTRAC’s supervisory focus in the professional services sector will reflect this.

Week 7 to 8: Build Your Beneficial Ownership Framework

Beneficial ownership verification is the compliance obligation most frequently cited in AUSTRAC enforcement actions. Your program must specify how you will identify the natural persons who ultimately own or control each entity client.

For companies, you must trace the ownership chain until you reach the natural persons who hold 25 per cent or more. For trusts, you must identify the trustee, settlor, and beneficiaries. For partnerships, you must identify each partner. Where ownership is complex or obscured, enhanced due diligence is required.

Document your approach, including what you do when a client is unable or unwilling to provide beneficial ownership information. Your program must specify that you will not provide services to clients you cannot adequately identify.

an image of a baobab tree against the sunset, symbolising the success business can achieve by engaging the AML/CTF compliance program services from DBA Advisory

Week 9 to 10: Staff Training and Documentation

AUSTRAC requires that all staff involved in providing designated services receive AML/CTF training. Training must cover the obligations under the AML/CTF Act, how to identify suspicious behaviour, how to lodge a suspicious matter report without tipping off the customer, and your firm’s internal escalation procedures.

Training must be documented, who received it, when, and what it covered. New staff must be trained before they begin work on designated services. Existing staff must receive refresher training when your program or the regulations are updated.

Your program document should include a training register and a record of program updates. AUSTRAC will ask for this evidence during a supervisory review.

What AUSTRAC Looks For in a Supervisory Review

AUSTRAC’s supervisory reviews examine whether your program reflects practice, not just paper. Reviewers will interview staff to determine whether they understand the procedures. They will examine transaction records to assess whether your monitoring is operating. They will test your KYC files against your stated procedures.

The most common deficiencies found in professional services firms are: programs that were adopted but never updated after regulatory changes; KYC files that are incomplete or rely on expired documents; no evidence of staff training; transaction monitoring that is manual and undocumented; and beneficial ownership verification that stops at the first corporate layer.

Building an AML/CTF compliance program

The step firms treat as preliminary is the one reviewers test hardest. Part B has to follow from Part A: if your risk assessment rates trust structures as high risk and your verification procedures treat them like everything else, the program contradicts itself on its own terms. That inconsistency is visible without interviewing a single staff member.

The sequence is the point: risk assessment in weeks one and two, the program document in three and four, KYC and CDD procedures in five and six, beneficial ownership in seven and eight, and training with its documentation in nine and ten. What AUSTRAC assesses at the end of it is practice rather than paper, so build each stage as something the firm will actually do.

an image of a fisherman throwning a net into the water while the sun sets in the background, symbolising AML/CTF compliance program requirements.

How DBA Advisory supports

An AML/CTF compliance program is a written program covering risk assessment, customer due diligence, ongoing monitoring, reporting, staff training and independent review. It must be adopted by the governing body and maintained as circumstances change, not written once.

DBA Advisory offers fixed-fee AML/CTF program build and compliance review engagements with no hidden costs — fixed-fee basis, with scope agreed after a short discovery conversation so you know what you are committing to before anything starts.

Frequently Asked Questions (FAQs)

An AML/CTF compliance program is a written document that every reporting entity under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 must adopt. It sets out how the entity identifies and manages money laundering and terrorism financing risk, including customer identification procedures, transaction monitoring, staff training, and suspicious matter reporting obligations.

From 1 July 2026, the AML/CTF regime expands to include accountants, lawyers, conveyancers, real estate agents, trust and company service providers, and dealers in precious metals and stones, the Tranche 2 sectors. These entities must register with AUSTRAC and adopt a compliant program within the timeframes set out in the legislation.

A firm working methodically through the required stages can build a compliant program in 60 days. The key steps are: ML/TF risk assessment (weeks 1-2), program drafting (weeks 3-4), KYC and CDD procedures (weeks 5-6), beneficial ownership framework (weeks 7-8), and staff training (weeks 9-10). Firms with complex service offerings or higher-risk client bases should allow additional time.

No. AUSTRAC's guidance is explicit that a program must reflect the specific nature of your firm's services, clients, and risk profile. A generic template that does not address your designated services, customer types, and risk assessment findings will not satisfy a supervisory review. Programs must be tailored to the firm.

AUSTRAC can issue infringement notices, accept enforceable undertakings, or pursue civil penalty proceedings. For serious or systemic non-compliance, penalties can reach tens of millions of dollars. AUSTRAC's enforcement approach focuses on whether firms have adopted and are maintaining a genuine, operational compliance program.

How DBA AML Supports You

This work is delivered by DBA AML Group Pty Ltd, the specialist AML/CTF compliance entity within DBA Advisory. It is a service where real AML/CTF practitioners do the work, so what leaves your desk is the function itself, not a portal to configure and operate. You remain the reporting entity; the operations move.

DBA AML Group Pty Ltd · ACN 697 643 404 · hello@dbaaml.com · dbaaml.com · We respond within one business day. Scope and fees are confirmed after a discovery call.

Disclaimer

© DBA Advisory 2026. This article is intended as general information only and does not constitute legal or compliance advice. Businesses should seek qualified advice specific to their circumstances before acting on any information contained in this article.

Not sure where your firm stands under Tranche 2? The AML/CTF Compliance Readiness Assessment is a scored, plain-English self-assessment you can complete in fifteen minutes. Download it free or book a meeting today!

We build the resilient foundations
empowering you to scale your business
Related content
an image of a volcano and dried lava with fumes or gas symbolizing Achieving Operational Resilience
Operational resilience for professional services firms requires more than disaster recovery. DBA Advisory's five-pillar maturity framework shows what institutional control actually looks like.
an image a snow- covered mountain, symbolising White Labelling vs Outsourcing
White labelling vs outsourcing in Australia: understand all three models, the legal risks post-Doessel, and which is right for your business. DBA Advisory's definitive guide.
an image of a female tennis player about to hit an on coming tennis ball, symbolising Global talent arbitrage and the serious governance risks post-Doessel
Global talent arbitrage in Australia carries serious governance risks post-Doessel. DBA Advisory's institutional framework turns offshore talent into a strategic asset safely.
Get in touch
Untitled-22
Alquin Dagamina

Manager Business Transformation and Technology Services Division