Disclaimer: This content is for informational purposes only and does not constitute legal advice. For advice specific to your circumstances, consult a qualified legal professional or contact AUSTRAC directly.

AML/CTF Compliance

AML/CTF Program for Remittance Providers

Compliance Desk
11 min read
AML/CTF Program for Remittance Providers

Photo by bdspn

Building an effective AML/CTF program is the cornerstone of operating a compliant remittance business in Australia. Your program must demonstrate to AUSTRAC that you can identify, mitigate and manage money laundering and terrorism financing risks specific to your remittance operations.

This guide provides practical templates, checklists and real-world examples to help you develop a program that meets AUSTRAC's expectations while remaining proportionate to your business size and risk profile.

Key Takeaways

  • Part A of your AML/CTF program covers risk assessment, customer identification, transaction monitoring and reporting — these are your core operational procedures
  • Part B focuses on governance, training, employee screening and independent review — the oversight framework that ensures Part A works effectively
  • Risk-based approach means smaller MTOs can have simpler programs — AUSTRAC expects proportionality, not one-size-fits-all
  • Annual review is mandatory, with material changes requiring immediate updates — your program is a living document
  • Templates save time but must be customised — generic programs are a red flag during AUSTRAC assessments

Understanding the Two-Part Structure

Every remittance provider must have a written AML/CTF program split into two distinct parts. This structure isn't arbitrary — it reflects how AUSTRAC approaches compliance assessment.

Part A: Risk Assessment and Customer Procedures

Part A forms the operational backbone of your compliance framework. It documents how you assess ML/TF risks and what procedures you follow when onboarding customers, monitoring transactions and submitting reports.

For remittance providers, Part A typically runs 15-30 pages for smaller operators and 40-80 pages for larger businesses with multiple corridors. The length matters less than the specificity — AUSTRAC wants to see procedures tailored to your actual operations.

Part B: Governance and Oversight

Part B establishes the governance framework that ensures Part A procedures are followed consistently. This includes your AML/CTF compliance officer appointment, staff training programs, employee due diligence and independent review arrangements.

Most remittance providers find Part B shorter than Part A — typically 10-20 pages. However, the governance requirements are equally critical, as they demonstrate board-level commitment to compliance.

Building Your Part A: Risk-Based Procedures

ML/TF Risk Assessment Framework

Your risk assessment must evaluate money laundering and terrorism financing risks across four mandatory dimensions:

1. Customer Risk

  • Customer types (individuals, businesses, trusts)
  • Geographic risk based on residence/nationality
  • Occupation and source of funds
  • Expected transaction behaviour

2. Service/Product Risk

  • Cash vs electronic funding methods
  • Speed of transfer (same-day vs delayed)
  • Value limits and frequency
  • Destination accessibility

3. Delivery Channel Risk

  • Face-to-face vs online onboarding
  • Agent network risks
  • Mobile app vulnerabilities
  • Third-party platform dependencies

4. Jurisdiction Risk

  • Sanctions and embargo lists
  • FATF grey/black listings
  • Corruption perception indices
  • Terrorism financing concerns

Sample Risk Matrix for Remittance Providers:

Risk FactorLow RiskMedium RiskHigh Risk
Customer TypeSalaried employees, pensionersSelf-employed, studentsPEPs, cash-intensive businesses
Transaction SizeUnder $1,000$1,000-$5,000Above $5,000
CorridorUK, SingaporeIndia, PhilippinesPakistan, Lebanon
Funding MethodBank transferDebit cardCash deposit
FrequencyMonthlyWeeklyDaily/multiple daily

Customer Identification Procedures

Your KYC procedures must specify exactly what information you collect and verify for different customer types and risk levels.

Minimum KYC Requirements (All Customers):

  • Full legal name
  • Date of birth
  • Residential address
  • Identification document (driver's licence, passport, Medicare card)

Enhanced Due Diligence Triggers:

  • Transactions over $10,000 (single or cumulative)
  • High-risk jurisdictions (specify your list)
  • Politically exposed persons (PEPs)
  • Adverse media or sanctions matches
  • Unusual transaction patterns

Verification Methods Table:

Document TypeAcceptable SourcesVerification Method
IdentityAustralian driver's licence, passportDVS check or certified copy
AddressBank statement, utility billLess than 3 months old
IncomePayslip, tax returnFor transactions over $5,000
BusinessABN lookup, ASIC extractCurrent company extract

Transaction Monitoring Procedures

Your transaction monitoring system must detect suspicious patterns specific to remittance operations:

Common Monitoring Scenarios:

  1. Structuring/Smurfing

    • Multiple transactions just under $10,000
    • Same sender using variations of name
    • Multiple senders to same beneficiary
  2. Rapid Movement

    • Funds received and immediately sent
    • No apparent economic purpose
    • Unusual for customer profile
  3. Geographic Inconsistencies

    • Sending patterns don't match stated purpose
    • Beneficiaries in multiple high-risk countries
    • Routing through unexpected jurisdictions

Sample Monitoring Rules:

- Flag: 3+ transactions in 24 hours totalling >$9,000
- Flag: New customer sending >$5,000 in first transaction
- Flag: Dormant account suddenly active with large transfer
- Flag: Multiple customers using same phone/email
- Flag: Beneficiary receiving from 5+ senders in 30 days

Reporting Obligations

Your program must detail procedures for all AUSTRAC reporting requirements:

1. International Funds Transfer Instructions (IFTIs)

  • Report within 10 business days
  • Include all mandatory fields
  • Batch or individual submission process

2. Suspicious Matter Reports (SMRs)

  • Report within 24 hours of forming suspicion (best practice)
  • Maximum 3 business days (legal requirement)
  • Include comprehensive grounds for suspicion

3. Threshold Transaction Reports (TTRs)

  • Cash transactions of $10,000 or more
  • Report within 10 business days
  • Aggregate related transactions

Reporting Checklist Template:

  • Suspicious activity identified by: ____________
  • Date/time suspicion formed: ____________
  • Internal escalation completed: ____________
  • SMR reference number: ____________
  • Customer tipping-off controls applied
  • Follow-up actions determined

Building Your Part B: Governance Framework

AML/CTF Compliance Officer

Your Part B must formally appoint an AML/CTF compliance officer and define their responsibilities:

Mandatory Duties:

  • Oversight of the AML/CTF program
  • AUSTRAC liaison and correspondence
  • Board/senior management reporting
  • Program review and updates
  • Training coordination
  • Incident management

Best Practice Organisational Structure:

Board/Directors
    |
CEO/Managing Director
    |
AML/CTF Compliance Officer
    |
├── Operations Team
├── Customer Service
└── Finance/Accounts

Employee Due Diligence

Part B must specify screening procedures for employees in customer-facing or high-risk roles:

Pre-Employment Checks:

  • Criminal history (national police check)
  • Bankruptcy and credit checks
  • Reference verification
  • Sanctions screening

Ongoing Monitoring:

  • Annual re-screening for high-risk positions
  • Change in circumstances reporting
  • Conflict of interest declarations

Training Program

Your training program must ensure all staff understand their AML/CTF obligations:

Initial Training Requirements:

  • Completed within 2 weeks of starting
  • Cover ML/TF risks specific to remittance
  • Include practical scenarios
  • Test comprehension

Ongoing Training Schedule:

  • Annual refresher for all staff
  • Role-specific modules
  • Updates for regulatory changes
  • Records of attendance and completion

Sample Training Modules:

ModuleTarget AudienceFrequencyDuration
AML/CTF BasicsAll staffOnboarding + Annual2 hours
KYC ProceduresCustomer-facingOnboarding + 6-monthly3 hours
Transaction MonitoringOperations teamQuarterly2 hours
SMR WritingCompliance team6-monthly4 hours
Sanctions ScreeningAll customer-facingQuarterly updates1 hour

Independent Review

AUSTRAC expects regular independent review of your AML/CTF program:

Review Frequency:

  • Annually for established operators
  • Every 6 months for new businesses
  • After significant changes or incidents

Review Scope Checklist:

  • Part A procedures against actual practice
  • Sample testing of KYC files
  • Transaction monitoring effectiveness
  • Reporting timeliness and accuracy
  • Training records and effectiveness
  • Board reporting and oversight
  • Previous recommendations implemented

Implementation Timeline and Costs

Development Timeline

Building a compliant AML/CTF program typically follows this timeline:

Weeks 1-2: Risk Assessment

  • Analyse your business model
  • Identify customer segments
  • Map remittance corridors
  • Assess delivery channels

Weeks 3-4: Part A Drafting

  • Document KYC procedures
  • Define monitoring rules
  • Create reporting workflows
  • Develop forms and checklists

Weeks 5-6: Part B Development

  • Appoint compliance officer
  • Design training program
  • Establish governance structure
  • Plan independent review

Week 7-8: Review and Finalisation

  • Legal/consultant review
  • Board approval
  • Staff communication
  • Implementation planning

Cost Estimates

ComponentDIY CostConsultant CostOngoing Annual
Program Development80-120 hours staff time$5,000-$15,000$2,000-$5,000 updates
Legal ReviewN/A$2,000-$5,000$1,000-$2,000
Independent ReviewN/A$3,000-$8,000$3,000-$8,000
Training Materials40-60 hours$3,000-$6,000$1,000-$3,000
Templates/Software$500-$2,000Included$500-$2,000
Total First Year$500-$2,000 + time$13,000-$36,000$7,500-$20,000

Common Pitfalls and How to Avoid Them

1. Generic Programs

Problem: Using an off-the-shelf template without customisation Solution: Tailor every section to your specific operations, corridors and customer base

2. Set and Forget

Problem: Not updating the program after implementation Solution: Schedule quarterly reviews and update after any business changes

3. Theory vs Practice

Problem: Written procedures don't match actual operations Solution: Test procedures with real scenarios before finalising

4. Insufficient Board Engagement

Problem: Compliance officer working in isolation Solution: Mandatory quarterly board reporting on AML/CTF matters

5. Weak Transaction Monitoring

Problem: Over-reliance on manual checks Solution: Implement rule-based monitoring even if starting simple

2026 Reform Implications

The AML/CTF Reform Act 2026 introduces several changes affecting your program:

Simplified Customer Due Diligence:

  • New risk-based CDD thresholds
  • Digital identity acceptance expanded
  • Beneficial ownership requirements clarified

Enhanced Reporting:

  • Tipping-off exceptions broadened
  • Information sharing provisions
  • Cross-border correspondent requirements

Transition Provisions:

  • 3-year window to update existing programs
  • Immediate adoption permitted
  • Guidance expected by July 2026

Practical Templates and Tools

Successful implementation requires practical tools. Here are essential templates every remittance provider needs:

1. Risk Assessment Matrix

  • Customer risk scoring
  • Corridor risk ratings
  • Product risk evaluation
  • Combined risk calculation

2. KYC Checklist

  • Document requirements by risk level
  • Verification procedures
  • Record-keeping requirements
  • Escalation triggers

3. Transaction Monitoring Rules

  • Scenario descriptions
  • Threshold settings
  • Investigation procedures
  • Disposition codes

4. Training Records

  • Attendance tracking
  • Competency assessment
  • Refresher scheduling
  • Topic coverage matrix

Next Steps

Building an effective AML/CTF program requires commitment but provides the foundation for sustainable remittance operations. Start with a thorough risk assessment of your specific business model, then build procedures that address those risks proportionately.

Remember that AUSTRAC values substance over form — a concise, well-implemented program beats a lengthy document that sits on the shelf.

For additional support, consider using Australia Remittance's AML/CTF Program Builder or reviewing our corridor-specific guides for targeted risk considerations.

This information is general in nature and does not constitute legal advice. Consult AUSTRAC or a qualified legal professional for advice specific to your situation.

Frequently Asked Questions

Do I need both Part A and Part B from day one?

Yes, AUSTRAC requires both parts to be in place before you begin providing designated services. You cannot operate with just Part A or phase in Part B later — both must be approved by your board and implemented before your first customer transaction.

Can I use another MTO's program as a template?

While you can review other programs for structure and ideas, directly copying another MTO's program is dangerous. AUSTRAC expects your program to reflect your specific business model, risk profile and corridors. Generic or copied programs are a major red flag during assessments.

How often must I review and update my AML/CTF program?

At minimum, you must review your program annually. However, you must also update it immediately when you make material changes to your business — new corridors, new products, new delivery channels or significant changes in transaction volumes all trigger an update requirement.

What happens if AUSTRAC finds problems with my program?

AUSTRAC typically provides an opportunity to remediate deficiencies before taking enforcement action. You'll receive a remedial direction specifying issues and timeframes for correction. Failure to comply can result in civil penalties up to $22.2 million for bodies corporate or criminal prosecution for serious breaches.

AML/CTFcomplianceAUSTRACrisk assessmentremittance regulation
Was this helpful?