Disclaimer: This content is for informational purposes only and does not constitute legal advice. For advice specific to your circumstances, consult a qualified legal professional or contact AUSTRAC directly.

AML/CTF Compliance

How to Write an AML/CTF Program Under the 2026 Rules: Template and Walkthrough

Compliance Desk
13 min read
How to Write an AML/CTF Program Under the 2026 Rules: Template and Walkthrough

Photo by prostophotokate

Writing an AML/CTF program under the 2026 reformed rules requires you to create a single, integrated document that addresses customer due diligence, transaction monitoring, and risk management in a cohesive framework. The new rules eliminate the old Part A/Part B structure and introduce clearer obligations for board oversight, simplified customer identification, and risk-based controls.

The challenge for Australian remittance operators isn't just meeting minimum requirements — it's creating a program that AUSTRAC reviewers will approve on first submission while remaining practical enough for daily operations. With civil penalties up to AUD 26.64 million for non-compliance, getting your program right matters more than ever.

Key Takeaways

  • The 2026 reforms replace the Part A/Part B structure with a single AML/CTF program document
  • Your program must cover six core components: risk assessment, CDD procedures, transaction monitoring, reporting obligations, governance, and record-keeping
  • Board approval is mandatory for all programs, with annual reviews required
  • Risk-based approach means your controls must match your specific business model and corridors
  • AUSTRAC expects programs to be living documents — update within 30 days of material changes

Structure of an AML/CTF Program Under 2026 Rules

The reformed AML/CTF program structure consolidates what were previously separate documents into one comprehensive framework. Your program must address all designated services you provide, from remittance dealing to currency exchange.

Core Components Required

Your AML/CTF program must include these six essential components:

1. ML/TF Risk Assessment

  • Business-wide risk evaluation
  • Customer risk categories (low, medium, high, prohibited)
  • Product and channel risk ratings
  • Corridor-specific risks (sanctions, FATF grey/blacklist)
  • Review frequency (minimum annual)

2. Customer Due Diligence (CDD) Procedures

  • Identity verification methods
  • Beneficial ownership requirements
  • Enhanced due diligence triggers
  • Ongoing monitoring parameters
  • Simplified CDD criteria (if applicable)

3. Transaction Monitoring Systems

  • Monitoring rules and thresholds
  • Alert investigation procedures
  • Escalation pathways
  • System testing schedule
  • Manual review processes

4. Reporting Obligations

  • SMR submission procedures
  • TTR automation (if applicable)
  • IFTI/IVTS reporting workflows
  • Internal reporting lines
  • Regulatory liaison protocols

5. Governance and Accountability

  • Board oversight requirements
  • AML/CTF Compliance Officer role
  • Staff training program
  • Independent review schedule
  • Breach reporting procedures

6. Record-Keeping Framework

  • CDD document retention (7 years)
  • Transaction records management
  • Program version control
  • Audit trail requirements
  • Data protection measures

Step-by-Step Writing Process

Step 1: Conduct Your ML/TF Risk Assessment

Before writing any procedures, complete a comprehensive risk assessment of your remittance business. This assessment forms the foundation for all risk-based decisions in your program.

Risk Assessment Template Structure:

Risk CategoryFactors to AssessRisk Rating
Customer TypesWalk-ins, online, business, agentsHigh/Medium/Low
CorridorsSanctions exposure, FATF listingsHigh/Medium/Low
ProductsCash-based, digital, high-valueHigh/Medium/Low
ChannelsBranch, online, mobile, agentsHigh/Medium/Low
GeographyRegional concentration, border proximityHigh/Medium/Low

Document your methodology clearly. AUSTRAC expects you to explain not just your risk ratings but how you arrived at them. For example: "Philippines corridor rated HIGH due to: (1) inclusion on FATF grey list until 2024, (2) cash-intensive economy with 70% unbanked population, (3) presence of designated terrorist groups in southern regions."

Step 2: Draft Customer Due Diligence Procedures

The 2026 reforms introduce the Customer Due Diligence (CDD) framework, replacing the old customer identification procedures. Your CDD section must specify exactly how you'll verify customer identity and assess risk.

Standard CDD Requirements:

For Individual Customers:
1. Full legal name
2. Date of birth
3. Current residential address
4. Verification through:
   - Government-issued photo ID (primary)
   - Electronic verification via VEDA/Equifax (alternative)
   - Biometric verification for digital onboarding

For Business Customers:
1. Legal entity name and ABN/ACN
2. Registered office address
3. Nature of business
4. Beneficial owners (25%+ ownership)
5. Verification through:
   - ASIC company extract
   - ABR lookup
   - Beneficial ownership declaration

Enhanced CDD Triggers:

  • Transactions over AUD 10,000 in a calendar month
  • High-risk corridors (specify your list)
  • Politically exposed persons (PEPs)
  • Complex ownership structures
  • Adverse media or sanctions hits

Include specific procedures for each trigger. For example: "When a customer sends cumulative transfers exceeding AUD 10,000 to Pakistan within 30 days, conduct enhanced CDD including: (1) source of funds verification via bank statements, (2) purpose of remittance documentation, (3) beneficiary relationship confirmation."

Step 3: Design Transaction Monitoring Rules

Your transaction monitoring section must detail both automated and manual review processes. Be specific about thresholds and investigation procedures.

Sample Monitoring Rules:

Rule NameThresholdInvestigation Required
Rapid Movement3+ transactions within 24 hoursReview pattern, verify identity
StructuringMultiple transactions just under AUD 10,000Check for TTR avoidance
Dormant ReactivationNo activity 6+ months, then sudden high volumeFull CDD refresh
Corridor Velocity50% increase in corridor volume week-on-weekEnhanced beneficiary checks
Round Amounts5+ round amount transfers (e.g., exactly AUD 5,000)Purpose verification

Investigation Workflow:

  1. Alert generated (automated or manual)
  2. Level 1 review within 24 hours
  3. Escalation criteria defined
  4. Level 2 review by Compliance Officer within 48 hours
  5. SMR decision within 3 business days
  6. Documentation requirements

Step 4: Establish Reporting Procedures

The 2026 reforms maintain existing reporting obligations while introducing clearer timelines and quality expectations.

Suspicious Matter Reports (SMRs):

Submission Timeline:
- Form within 3 business days of forming suspicion
- Submit via AUSTRAC Online
- No customer tipping off

Quality Standards:
- Clear description of suspicious activity
- All relevant transaction details
- Supporting documentation attached
- Follow-up information within 24 hours if requested

Threshold Transaction Reports (TTRs):

Automatic Submission for:
- Cash transactions AUD 10,000+
- Multiple cash transactions totalling AUD 10,000+ in a day

Submission via:
- API integration (for high-volume operators)
- Batch upload daily
- Manual entry for exceptions

Step 5: Define Governance Structure

The 2026 reforms mandate board-level accountability for AML/CTF compliance. Your governance section must clearly define roles and oversight mechanisms.

Board Responsibilities:

  • Approve initial AML/CTF program
  • Review program annually (minimum)
  • Approve material changes within 30 days
  • Receive quarterly compliance reports
  • Oversee independent review findings

AML/CTF Compliance Officer Requirements:

  • Senior management position
  • Direct reporting line to board/CEO
  • Sufficient resources and authority
  • No operational conflicts of interest
  • Defined deputies for absence coverage

Training Program Matrix:

RoleFrequencyContentAssessment
Frontline staffOnboarding + annualCDD, red flags, reportingOnline quiz 80% pass
Compliance teamQuarterlyRegulatory updates, trendsCase studies
Senior managementBiannualRisk oversight, obligationsScenario testing
BoardAnnualProgram effectiveness, risksStrategic review

Step 6: Implement Record-Keeping Protocols

Your record-keeping section must address both regulatory requirements and operational needs.

Mandatory Retention Periods:

  • Customer identification records: 7 years after relationship ends
  • Transaction records: 7 years after transaction date
  • Risk assessments: 7 years after superseded
  • Training records: 7 years after employee departure
  • SMRs and correspondence: 7 years after submission

Storage Requirements:

  • Electronic records in searchable format
  • Encryption for sensitive data
  • Access controls with audit logs
  • Backup procedures (daily minimum)
  • Ability to produce records within 3 business days

Writing Tips for AUSTRAC Approval

Use Clear, Operational Language

Avoid legal jargon that frontline staff won't understand. Instead of "The reporting entity shall implement risk-based customer due diligence procedures commensurate with identified ML/TF risks," write "Check higher-risk customers more thoroughly. For customers sending to sanctioned countries, verify their source of funds with bank statements."

Include Practical Examples

AUSTRAC reviewers look for evidence that you understand how requirements apply to your specific business. Include examples relevant to your corridors:

"Example: A customer wants to send AUD 15,000 to Lebanon for medical expenses. Because Lebanon is a high-risk corridor due to sanctions, we will:

  1. Obtain medical invoices from the Lebanese hospital
  2. Verify the hospital is not sanctions-listed
  3. Confirm the customer's relationship to the patient
  4. Document the source of funds
  5. Monitor future transactions to ensure consistency"

Address Your Specific Risks

Generic programs get rejected. If you operate Pacific corridors, address specific risks like:

  • Seasonal remittance patterns (Christmas, cultural obligations)
  • Limited banking infrastructure in receiving countries
  • Cash-intensive economies
  • Family support vs commercial transactions

Show Continuous Improvement

Include review and update procedures: "The Compliance Officer reviews monitoring rules monthly, analysing:

  • False positive rates (target <30%)
  • Alert investigation times (target <48 hours)
  • SMR quality feedback from AUSTRAC
  • Emerging typologies from FINTEL Alliance"

Common Pitfalls to Avoid

Copying Generic Templates

AUSTRAC immediately identifies copied templates. Your program must reflect your actual operations. If you don't offer business accounts, don't include business customer procedures. If you only serve three corridors, focus your risk assessment on those specific countries.

Ignoring Technology Limitations

Be honest about your systems. If you use manual transaction monitoring, detail your review processes. Don't claim automated monitoring capabilities you don't have. AUSTRAC prefers well-documented manual processes over fictional automation.

Underestimating Training Requirements

Many programs fail because they propose unrealistic training. If you have five staff, don't commit to monthly two-day training sessions. Instead, propose practical approaches like:

  • 15-minute daily huddles on compliance topics
  • Monthly 1-hour training sessions
  • Quarterly scenario exercises
  • Annual full-day compliance workshop

Missing Agent Oversight

If you use agents, your program must detail oversight procedures:

  • Agent due diligence before appointment
  • Training requirements and records
  • Transaction monitoring across agent network
  • Audit schedule (risk-based frequency)
  • Termination procedures for non-compliance

Template Structure for 2026 AML/CTF Program

Here's a practical template structure that meets AUSTRAC requirements:

1. PROGRAM OVERVIEW
   1.1 Business Description
   1.2 Designated Services Provided
   1.3 Program Approval and Maintenance
   1.4 Definitions and Abbreviations

2. ML/TF RISK ASSESSMENT
   2.1 Risk Assessment Methodology
   2.2 Customer Risk Categories
   2.3 Product and Channel Risks
   2.4 Geographic/Corridor Risks
   2.5 Overall Risk Profile
   2.6 Risk Review Schedule

3. CUSTOMER DUE DILIGENCE
   3.1 Standard CDD Requirements
   3.2 Enhanced CDD Triggers and Procedures
   3.3 Simplified CDD (if applicable)
   3.4 Beneficial Ownership
   3.5 Ongoing CDD and Reviews
   3.6 Prohibited Customers

4. TRANSACTION MONITORING
   4.1 Monitoring Rules and Parameters
   4.2 Alert Investigation Procedures
   4.3 Escalation and Decision Making
   4.4 System Testing and Tuning
   4.5 Manual Review Processes

5. REPORTING OBLIGATIONS
   5.1 Suspicious Matter Reports
   5.2 Threshold Transaction Reports
   5.3 International Funds Transfer Instructions
   5.4 Compliance Reports to Board
   5.5 Regulatory Correspondence

6. GOVERNANCE AND OVERSIGHT
   6.1 Board Responsibilities
   6.2 Senior Management Accountability
   6.3 AML/CTF Compliance Officer
   6.4 Three Lines of Defence
   6.5 Independent Review Program

7. TRAINING AND AWARENESS
   7.1 Training Needs Assessment
   7.2 Role-Based Training Matrix
   7.3 Training Delivery Methods
   7.4 Competency Assessment
   7.5 Training Records

8. RECORD KEEPING
   8.1 Retention Requirements
   8.2 Storage and Security
   8.3 Access Controls
   8.4 Production for Authorities
   8.5 Disposal Procedures

9. PROGRAM BREACHES AND REMEDIATION
   9.1 Breach Identification
   9.2 Assessment and Reporting
   9.3 Remediation Procedures
   9.4 Preventive Measures
   9.5 Lessons Learned Process

10. APPENDICES
    A. Risk Assessment Methodology
    B. CDD Checklist Templates
    C. Red Flag Indicators
    D. Escalation Contact Lists
    E. Regulatory References

Approval Process and Timeline

Board Approval Requirements

Under the 2026 reforms, your board (or equivalent governing body) must formally approve your AML/CTF program before implementation. For sole traders, you must document your approval as the business owner.

Board Approval Checklist:

  • Full program reviewed by all board members
  • Risk assessment findings understood
  • Resource requirements approved
  • Compliance Officer appointed with sufficient authority
  • Review schedule established (minimum annual)
  • Minutes documenting approval decision

AUSTRAC Notification Timeline

While you don't need pre-approval from AUSTRAC, you must:

  1. Implement your approved program immediately
  2. Notify AUSTRAC of adoption within 14 days
  3. Provide a copy upon request (within 3 business days)
  4. Update AUSTRAC on material changes within 30 days

Living Document Management

Trigger Events for Updates

Your program must be updated within 30 days of:

  • New corridor launches
  • Product or service changes
  • Regulatory amendments
  • Significant compliance breaches
  • Risk profile changes
  • System or process upgrades

Version Control Best Practices

Maintain clear version control:

Version: 2.0
Approval Date: 15 April 2026
Effective Date: 1 May 2026
Next Review: 1 May 2027
Changes: Updated CDD procedures for digital onboarding,
         added Pakistan corridor risk assessment,
         enhanced PEP screening requirements

Technology Considerations

Integration with Compliance Systems

Your program should reference specific technologies:

  • Identity verification providers (e.g., GreenID, IDMatrix)
  • Sanctions screening tools (e.g., Dow Jones, Refinitiv)
  • Transaction monitoring platforms (e.g., ComplyAdvantage, Fiserv)
  • Record-keeping systems (e.g., SharePoint, compliance-specific platforms)

Include fallback procedures for system outages: "If automated sanctions screening is unavailable, manually check against DFAT consolidated list and UN sanctions database before processing any transaction."

API and Reporting Automation

For larger operators, detail your automated reporting:

  • AUSTRAC Online API integration for SMRs/TTRs
  • Daily batch processing schedules
  • Exception handling procedures
  • Data quality controls
  • Reconciliation processes

Frequently Asked Questions

Do I still need separate Part A and Part B documents under the 2026 rules?

No. The 2026 reforms eliminate the Part A/Part B structure. You now create a single, integrated AML/CTF program that covers all elements previously split between the two parts. This consolidated approach reduces duplication and creates clearer accountability.

What happens if I'm already operating when the new rules take effect?

Existing operators have a 12-month transition period from 31 March 2026 to update their programs. However, you must comply with new requirements immediately where they're more stringent than old rules. AUSTRAC recommends starting your program update at least 3 months before the deadline.

Can I use AUSTRAC's template or do I need to create my own?

While AUSTRAC provides guidance and examples, you must create a program specific to your business. Generic templates get rejected because they don't address your unique risks, corridors, and operations. Use AUSTRAC's guidance as a framework, but customise everything to your circumstances.

How detailed should my transaction monitoring rules be?

Your monitoring rules should be specific enough for staff to apply consistently but flexible enough to adapt to emerging risks. Include exact thresholds (e.g., "3 transactions within 24 hours"), investigation steps, and escalation criteria. Avoid vague statements like "monitor for unusual activity" without defining what constitutes "unusual" for your business.

Taking Action

Writing your AML/CTF program under the 2026 rules requires balancing regulatory compliance with operational reality. Start with an honest risk assessment, build procedures your team can actually follow, and create documentation that demonstrates your commitment to compliance.

Remember that AUSTRAC values practical effectiveness over perfect paperwork. A well-implemented basic program beats an elaborate program that exists only on paper.

For program templates and compliance tools, visit our AML/CTF Program Builder. For updates on regulatory changes, subscribe to our compliance newsletter.

This information is general in nature and does not constitute legal advice. Consult AUSTRAC or a qualified legal professional for advice specific to your situation.

AML/CTFcomplianceAUSTRAC2026 reformsprogram writing
Was this helpful?