Building a Risk-Based AML/CTF Program

Written by , Principal Consultant
Reviewed: 19 September 2026
Australian Regulatory Guidance
Educational notice: This information is educational and general in nature. It is not legal advice and does not determine whether your business is a reporting entity. Your obligations depend on your services, circumstances, ML/TF risk and the law in force. Check the current AUSTRAC guidance and legislation linked below, and obtain qualified advice where needed.

An AML/CTF program is the operational framework a reporting entity uses to identify, assess, manage and mitigate money laundering, terrorism financing and proliferation financing risks. The reformed regime is outcomes-focused: the program must be risk-based, documented, implemented and kept effective rather than treated as a standard template.

Current operational guidance: AUSTRAC — Your AML/CTF program. Reform context: changes to AML/CTF program requirements.

What should an AML/CTF program achieve?

Your program should connect your business-wide risk assessment to the policies, procedures, systems and controls used in day-to-day work. It should explain who is accountable, how customer due diligence is applied, how suspicious activity is identified and reported, and how the framework is tested and improved.

What practical elements should the program cover?

  • Risk assessment: Identify and assess risks connected with customers, designated services, delivery channels and geographic exposure, then keep that assessment current.
  • Governance and accountability: Set clear oversight, decision rights, escalation paths and responsibilities for the AML/CTF compliance officer and governing body.
  • Customer due diligence: Define how the business identifies and verifies customers and beneficial owners, assesses customer risk, monitors relationships and applies enhanced measures.
  • Personnel and training: Apply appropriate personnel due diligence and give people performing AML/CTF functions training that is relevant to their role.
  • Reporting and records: Build workable processes for regulatory reports, record keeping and responding to AUSTRAC requirements.
  • Independent evaluation: Arrange regular independent evaluation of the program’s design, implementation and ongoing effectiveness as required by the current regime.

How should risk drive the controls?

The program should explain how assessed risk changes what the business does. Higher-risk situations may require more information, stronger verification, closer monitoring, senior approval or limits on the relationship. Lower-risk treatment must still be permitted by the Act and Rules and supported by the business’s assessment.

How do you make the program operational?

Translate each policy into owners, decision points, evidence and review triggers. Test the workflow against realistic scenarios, train the people who use it and fix gaps found through monitoring, incidents, independent evaluation or regulatory change. A document that does not match actual practice is not an effective control.

AML Ops Consulting

Practical AML, CTF and KYC support for businesses ready to replace uncertainty with a way of working that holds up.

Explore

Start a conversation

Book a clarity call

Educational information only. Advice is shaped around your business, obligations and operating reality.

© 2026 AML Ops ConsultingClarity first. Controls that work.