
Photo by bdspn
Building an effective AML/CTF program is the cornerstone of operating a compliant remittance business in Australia. Your program must demonstrate to AUSTRAC that you can identify, mitigate and manage money laundering and terrorism financing risks specific to your remittance operations.
This guide provides practical templates, checklists and real-world examples to help you develop a program that meets AUSTRAC's expectations while remaining proportionate to your business size and risk profile.
Key Takeaways
- Part A of your AML/CTF program covers risk assessment, customer identification, transaction monitoring and reporting — these are your core operational procedures
- Part B focuses on governance, training, employee screening and independent review — the oversight framework that ensures Part A works effectively
- Risk-based approach means smaller MTOs can have simpler programs — AUSTRAC expects proportionality, not one-size-fits-all
- Annual review is mandatory, with material changes requiring immediate updates — your program is a living document
- Templates save time but must be customised — generic programs are a red flag during AUSTRAC assessments
Understanding the Two-Part Structure
Every remittance provider must have a written AML/CTF program split into two distinct parts. This structure isn't arbitrary — it reflects how AUSTRAC approaches compliance assessment.
Part A: Risk Assessment and Customer Procedures
Part A forms the operational backbone of your compliance framework. It documents how you assess ML/TF risks and what procedures you follow when onboarding customers, monitoring transactions and submitting reports.
For remittance providers, Part A typically runs 15-30 pages for smaller operators and 40-80 pages for larger businesses with multiple corridors. The length matters less than the specificity — AUSTRAC wants to see procedures tailored to your actual operations.
Part B: Governance and Oversight
Part B establishes the governance framework that ensures Part A procedures are followed consistently. This includes your AML/CTF compliance officer appointment, staff training programs, employee due diligence and independent review arrangements.
Most remittance providers find Part B shorter than Part A — typically 10-20 pages. However, the governance requirements are equally critical, as they demonstrate board-level commitment to compliance.
Building Your Part A: Risk-Based Procedures
ML/TF Risk Assessment Framework
Your risk assessment must evaluate money laundering and terrorism financing risks across four mandatory dimensions:
1. Customer Risk
- Customer types (individuals, businesses, trusts)
- Geographic risk based on residence/nationality
- Occupation and source of funds
- Expected transaction behaviour
2. Service/Product Risk
- Cash vs electronic funding methods
- Speed of transfer (same-day vs delayed)
- Value limits and frequency
- Destination accessibility
3. Delivery Channel Risk
- Face-to-face vs online onboarding
- Agent network risks
- Mobile app vulnerabilities
- Third-party platform dependencies
4. Jurisdiction Risk
- Sanctions and embargo lists
- FATF grey/black listings
- Corruption perception indices
- Terrorism financing concerns
Sample Risk Matrix for Remittance Providers:
| Risk Factor | Low Risk | Medium Risk | High Risk |
|---|---|---|---|
| Customer Type | Salaried employees, pensioners | Self-employed, students | PEPs, cash-intensive businesses |
| Transaction Size | Under $1,000 | $1,000-$5,000 | Above $5,000 |
| Corridor | UK, Singapore | India, Philippines | Pakistan, Lebanon |
| Funding Method | Bank transfer | Debit card | Cash deposit |
| Frequency | Monthly | Weekly | Daily/multiple daily |
Customer Identification Procedures
Your KYC procedures must specify exactly what information you collect and verify for different customer types and risk levels.
Minimum KYC Requirements (All Customers):
- Full legal name
- Date of birth
- Residential address
- Identification document (driver's licence, passport, Medicare card)
Enhanced Due Diligence Triggers:
- Transactions over $10,000 (single or cumulative)
- High-risk jurisdictions (specify your list)
- Politically exposed persons (PEPs)
- Adverse media or sanctions matches
- Unusual transaction patterns
Verification Methods Table:
| Document Type | Acceptable Sources | Verification Method |
|---|---|---|
| Identity | Australian driver's licence, passport | DVS check or certified copy |
| Address | Bank statement, utility bill | Less than 3 months old |
| Income | Payslip, tax return | For transactions over $5,000 |
| Business | ABN lookup, ASIC extract | Current company extract |
Transaction Monitoring Procedures
Your transaction monitoring system must detect suspicious patterns specific to remittance operations:
Common Monitoring Scenarios:
-
Structuring/Smurfing
- Multiple transactions just under $10,000
- Same sender using variations of name
- Multiple senders to same beneficiary
-
Rapid Movement
- Funds received and immediately sent
- No apparent economic purpose
- Unusual for customer profile
-
Geographic Inconsistencies
- Sending patterns don't match stated purpose
- Beneficiaries in multiple high-risk countries
- Routing through unexpected jurisdictions
Sample Monitoring Rules:
- Flag: 3+ transactions in 24 hours totalling >$9,000
- Flag: New customer sending >$5,000 in first transaction
- Flag: Dormant account suddenly active with large transfer
- Flag: Multiple customers using same phone/email
- Flag: Beneficiary receiving from 5+ senders in 30 days
Reporting Obligations
Your program must detail procedures for all AUSTRAC reporting requirements:
1. International Funds Transfer Instructions (IFTIs)
- Report within 10 business days
- Include all mandatory fields
- Batch or individual submission process
2. Suspicious Matter Reports (SMRs)
- Report within 24 hours of forming suspicion (best practice)
- Maximum 3 business days (legal requirement)
- Include comprehensive grounds for suspicion
3. Threshold Transaction Reports (TTRs)
- Cash transactions of $10,000 or more
- Report within 10 business days
- Aggregate related transactions
Reporting Checklist Template:
- Suspicious activity identified by: ____________
- Date/time suspicion formed: ____________
- Internal escalation completed: ____________
- SMR reference number: ____________
- Customer tipping-off controls applied
- Follow-up actions determined
Building Your Part B: Governance Framework
AML/CTF Compliance Officer
Your Part B must formally appoint an AML/CTF compliance officer and define their responsibilities:
Mandatory Duties:
- Oversight of the AML/CTF program
- AUSTRAC liaison and correspondence
- Board/senior management reporting
- Program review and updates
- Training coordination
- Incident management
Best Practice Organisational Structure:
Board/Directors
|
CEO/Managing Director
|
AML/CTF Compliance Officer
|
├── Operations Team
├── Customer Service
└── Finance/Accounts
Employee Due Diligence
Part B must specify screening procedures for employees in customer-facing or high-risk roles:
Pre-Employment Checks:
- Criminal history (national police check)
- Bankruptcy and credit checks
- Reference verification
- Sanctions screening
Ongoing Monitoring:
- Annual re-screening for high-risk positions
- Change in circumstances reporting
- Conflict of interest declarations
Training Program
Your training program must ensure all staff understand their AML/CTF obligations:
Initial Training Requirements:
- Completed within 2 weeks of starting
- Cover ML/TF risks specific to remittance
- Include practical scenarios
- Test comprehension
Ongoing Training Schedule:
- Annual refresher for all staff
- Role-specific modules
- Updates for regulatory changes
- Records of attendance and completion
Sample Training Modules:
| Module | Target Audience | Frequency | Duration |
|---|---|---|---|
| AML/CTF Basics | All staff | Onboarding + Annual | 2 hours |
| KYC Procedures | Customer-facing | Onboarding + 6-monthly | 3 hours |
| Transaction Monitoring | Operations team | Quarterly | 2 hours |
| SMR Writing | Compliance team | 6-monthly | 4 hours |
| Sanctions Screening | All customer-facing | Quarterly updates | 1 hour |
Independent Review
AUSTRAC expects regular independent review of your AML/CTF program:
Review Frequency:
- Annually for established operators
- Every 6 months for new businesses
- After significant changes or incidents
Review Scope Checklist:
- Part A procedures against actual practice
- Sample testing of KYC files
- Transaction monitoring effectiveness
- Reporting timeliness and accuracy
- Training records and effectiveness
- Board reporting and oversight
- Previous recommendations implemented
Implementation Timeline and Costs
Development Timeline
Building a compliant AML/CTF program typically follows this timeline:
Weeks 1-2: Risk Assessment
- Analyse your business model
- Identify customer segments
- Map remittance corridors
- Assess delivery channels
Weeks 3-4: Part A Drafting
- Document KYC procedures
- Define monitoring rules
- Create reporting workflows
- Develop forms and checklists
Weeks 5-6: Part B Development
- Appoint compliance officer
- Design training program
- Establish governance structure
- Plan independent review
Week 7-8: Review and Finalisation
- Legal/consultant review
- Board approval
- Staff communication
- Implementation planning
Cost Estimates
| Component | DIY Cost | Consultant Cost | Ongoing Annual |
|---|---|---|---|
| Program Development | 80-120 hours staff time | $5,000-$15,000 | $2,000-$5,000 updates |
| Legal Review | N/A | $2,000-$5,000 | $1,000-$2,000 |
| Independent Review | N/A | $3,000-$8,000 | $3,000-$8,000 |
| Training Materials | 40-60 hours | $3,000-$6,000 | $1,000-$3,000 |
| Templates/Software | $500-$2,000 | Included | $500-$2,000 |
| Total First Year | $500-$2,000 + time | $13,000-$36,000 | $7,500-$20,000 |
Common Pitfalls and How to Avoid Them
1. Generic Programs
Problem: Using an off-the-shelf template without customisation Solution: Tailor every section to your specific operations, corridors and customer base
2. Set and Forget
Problem: Not updating the program after implementation Solution: Schedule quarterly reviews and update after any business changes
3. Theory vs Practice
Problem: Written procedures don't match actual operations Solution: Test procedures with real scenarios before finalising
4. Insufficient Board Engagement
Problem: Compliance officer working in isolation Solution: Mandatory quarterly board reporting on AML/CTF matters
5. Weak Transaction Monitoring
Problem: Over-reliance on manual checks Solution: Implement rule-based monitoring even if starting simple
2026 Reform Implications
The AML/CTF Reform Act 2026 introduces several changes affecting your program:
Simplified Customer Due Diligence:
- New risk-based CDD thresholds
- Digital identity acceptance expanded
- Beneficial ownership requirements clarified
Enhanced Reporting:
- Tipping-off exceptions broadened
- Information sharing provisions
- Cross-border correspondent requirements
Transition Provisions:
- 3-year window to update existing programs
- Immediate adoption permitted
- Guidance expected by July 2026
Practical Templates and Tools
Successful implementation requires practical tools. Here are essential templates every remittance provider needs:
1. Risk Assessment Matrix
- Customer risk scoring
- Corridor risk ratings
- Product risk evaluation
- Combined risk calculation
2. KYC Checklist
- Document requirements by risk level
- Verification procedures
- Record-keeping requirements
- Escalation triggers
3. Transaction Monitoring Rules
- Scenario descriptions
- Threshold settings
- Investigation procedures
- Disposition codes
4. Training Records
- Attendance tracking
- Competency assessment
- Refresher scheduling
- Topic coverage matrix
Next Steps
Building an effective AML/CTF program requires commitment but provides the foundation for sustainable remittance operations. Start with a thorough risk assessment of your specific business model, then build procedures that address those risks proportionately.
Remember that AUSTRAC values substance over form — a concise, well-implemented program beats a lengthy document that sits on the shelf.
For additional support, consider using Australia Remittance's AML/CTF Program Builder or reviewing our corridor-specific guides for targeted risk considerations.
This information is general in nature and does not constitute legal advice. Consult AUSTRAC or a qualified legal professional for advice specific to your situation.
Frequently Asked Questions
Do I need both Part A and Part B from day one?
Yes, AUSTRAC requires both parts to be in place before you begin providing designated services. You cannot operate with just Part A or phase in Part B later — both must be approved by your board and implemented before your first customer transaction.
Can I use another MTO's program as a template?
While you can review other programs for structure and ideas, directly copying another MTO's program is dangerous. AUSTRAC expects your program to reflect your specific business model, risk profile and corridors. Generic or copied programs are a major red flag during assessments.
How often must I review and update my AML/CTF program?
At minimum, you must review your program annually. However, you must also update it immediately when you make material changes to your business — new corridors, new products, new delivery channels or significant changes in transaction volumes all trigger an update requirement.
What happens if AUSTRAC finds problems with my program?
AUSTRAC typically provides an opportunity to remediate deficiencies before taking enforcement action. You'll receive a remedial direction specifying issues and timeframes for correction. Failure to comply can result in civil penalties up to $22.2 million for bodies corporate or criminal prosecution for serious breaches.


