
Photo by prostophotokate
Writing an AML/CTF program under the 2026 reformed rules requires you to create a single, integrated document that addresses customer due diligence, transaction monitoring, and risk management in a cohesive framework. The new rules eliminate the old Part A/Part B structure and introduce clearer obligations for board oversight, simplified customer identification, and risk-based controls.
The challenge for Australian remittance operators isn't just meeting minimum requirements — it's creating a program that AUSTRAC reviewers will approve on first submission while remaining practical enough for daily operations. With civil penalties up to AUD 26.64 million for non-compliance, getting your program right matters more than ever.
Key Takeaways
- The 2026 reforms replace the Part A/Part B structure with a single AML/CTF program document
- Your program must cover six core components: risk assessment, CDD procedures, transaction monitoring, reporting obligations, governance, and record-keeping
- Board approval is mandatory for all programs, with annual reviews required
- Risk-based approach means your controls must match your specific business model and corridors
- AUSTRAC expects programs to be living documents — update within 30 days of material changes
Structure of an AML/CTF Program Under 2026 Rules
The reformed AML/CTF program structure consolidates what were previously separate documents into one comprehensive framework. Your program must address all designated services you provide, from remittance dealing to currency exchange.
Core Components Required
Your AML/CTF program must include these six essential components:
1. ML/TF Risk Assessment
- Business-wide risk evaluation
- Customer risk categories (low, medium, high, prohibited)
- Product and channel risk ratings
- Corridor-specific risks (sanctions, FATF grey/blacklist)
- Review frequency (minimum annual)
2. Customer Due Diligence (CDD) Procedures
- Identity verification methods
- Beneficial ownership requirements
- Enhanced due diligence triggers
- Ongoing monitoring parameters
- Simplified CDD criteria (if applicable)
3. Transaction Monitoring Systems
- Monitoring rules and thresholds
- Alert investigation procedures
- Escalation pathways
- System testing schedule
- Manual review processes
4. Reporting Obligations
- SMR submission procedures
- TTR automation (if applicable)
- IFTI/IVTS reporting workflows
- Internal reporting lines
- Regulatory liaison protocols
5. Governance and Accountability
- Board oversight requirements
- AML/CTF Compliance Officer role
- Staff training program
- Independent review schedule
- Breach reporting procedures
6. Record-Keeping Framework
- CDD document retention (7 years)
- Transaction records management
- Program version control
- Audit trail requirements
- Data protection measures
Step-by-Step Writing Process
Step 1: Conduct Your ML/TF Risk Assessment
Before writing any procedures, complete a comprehensive risk assessment of your remittance business. This assessment forms the foundation for all risk-based decisions in your program.
Risk Assessment Template Structure:
| Risk Category | Factors to Assess | Risk Rating |
|---|---|---|
| Customer Types | Walk-ins, online, business, agents | High/Medium/Low |
| Corridors | Sanctions exposure, FATF listings | High/Medium/Low |
| Products | Cash-based, digital, high-value | High/Medium/Low |
| Channels | Branch, online, mobile, agents | High/Medium/Low |
| Geography | Regional concentration, border proximity | High/Medium/Low |
Document your methodology clearly. AUSTRAC expects you to explain not just your risk ratings but how you arrived at them. For example: "Philippines corridor rated HIGH due to: (1) inclusion on FATF grey list until 2024, (2) cash-intensive economy with 70% unbanked population, (3) presence of designated terrorist groups in southern regions."
Step 2: Draft Customer Due Diligence Procedures
The 2026 reforms introduce the Customer Due Diligence (CDD) framework, replacing the old customer identification procedures. Your CDD section must specify exactly how you'll verify customer identity and assess risk.
Standard CDD Requirements:
For Individual Customers:
1. Full legal name
2. Date of birth
3. Current residential address
4. Verification through:
- Government-issued photo ID (primary)
- Electronic verification via VEDA/Equifax (alternative)
- Biometric verification for digital onboarding
For Business Customers:
1. Legal entity name and ABN/ACN
2. Registered office address
3. Nature of business
4. Beneficial owners (25%+ ownership)
5. Verification through:
- ASIC company extract
- ABR lookup
- Beneficial ownership declaration
Enhanced CDD Triggers:
- Transactions over AUD 10,000 in a calendar month
- High-risk corridors (specify your list)
- Politically exposed persons (PEPs)
- Complex ownership structures
- Adverse media or sanctions hits
Include specific procedures for each trigger. For example: "When a customer sends cumulative transfers exceeding AUD 10,000 to Pakistan within 30 days, conduct enhanced CDD including: (1) source of funds verification via bank statements, (2) purpose of remittance documentation, (3) beneficiary relationship confirmation."
Step 3: Design Transaction Monitoring Rules
Your transaction monitoring section must detail both automated and manual review processes. Be specific about thresholds and investigation procedures.
Sample Monitoring Rules:
| Rule Name | Threshold | Investigation Required |
|---|---|---|
| Rapid Movement | 3+ transactions within 24 hours | Review pattern, verify identity |
| Structuring | Multiple transactions just under AUD 10,000 | Check for TTR avoidance |
| Dormant Reactivation | No activity 6+ months, then sudden high volume | Full CDD refresh |
| Corridor Velocity | 50% increase in corridor volume week-on-week | Enhanced beneficiary checks |
| Round Amounts | 5+ round amount transfers (e.g., exactly AUD 5,000) | Purpose verification |
Investigation Workflow:
- Alert generated (automated or manual)
- Level 1 review within 24 hours
- Escalation criteria defined
- Level 2 review by Compliance Officer within 48 hours
- SMR decision within 3 business days
- Documentation requirements
Step 4: Establish Reporting Procedures
The 2026 reforms maintain existing reporting obligations while introducing clearer timelines and quality expectations.
Suspicious Matter Reports (SMRs):
Submission Timeline:
- Form within 3 business days of forming suspicion
- Submit via AUSTRAC Online
- No customer tipping off
Quality Standards:
- Clear description of suspicious activity
- All relevant transaction details
- Supporting documentation attached
- Follow-up information within 24 hours if requested
Threshold Transaction Reports (TTRs):
Automatic Submission for:
- Cash transactions AUD 10,000+
- Multiple cash transactions totalling AUD 10,000+ in a day
Submission via:
- API integration (for high-volume operators)
- Batch upload daily
- Manual entry for exceptions
Step 5: Define Governance Structure
The 2026 reforms mandate board-level accountability for AML/CTF compliance. Your governance section must clearly define roles and oversight mechanisms.
Board Responsibilities:
- Approve initial AML/CTF program
- Review program annually (minimum)
- Approve material changes within 30 days
- Receive quarterly compliance reports
- Oversee independent review findings
AML/CTF Compliance Officer Requirements:
- Senior management position
- Direct reporting line to board/CEO
- Sufficient resources and authority
- No operational conflicts of interest
- Defined deputies for absence coverage
Training Program Matrix:
| Role | Frequency | Content | Assessment |
|---|---|---|---|
| Frontline staff | Onboarding + annual | CDD, red flags, reporting | Online quiz 80% pass |
| Compliance team | Quarterly | Regulatory updates, trends | Case studies |
| Senior management | Biannual | Risk oversight, obligations | Scenario testing |
| Board | Annual | Program effectiveness, risks | Strategic review |
Step 6: Implement Record-Keeping Protocols
Your record-keeping section must address both regulatory requirements and operational needs.
Mandatory Retention Periods:
- Customer identification records: 7 years after relationship ends
- Transaction records: 7 years after transaction date
- Risk assessments: 7 years after superseded
- Training records: 7 years after employee departure
- SMRs and correspondence: 7 years after submission
Storage Requirements:
- Electronic records in searchable format
- Encryption for sensitive data
- Access controls with audit logs
- Backup procedures (daily minimum)
- Ability to produce records within 3 business days
Writing Tips for AUSTRAC Approval
Use Clear, Operational Language
Avoid legal jargon that frontline staff won't understand. Instead of "The reporting entity shall implement risk-based customer due diligence procedures commensurate with identified ML/TF risks," write "Check higher-risk customers more thoroughly. For customers sending to sanctioned countries, verify their source of funds with bank statements."
Include Practical Examples
AUSTRAC reviewers look for evidence that you understand how requirements apply to your specific business. Include examples relevant to your corridors:
"Example: A customer wants to send AUD 15,000 to Lebanon for medical expenses. Because Lebanon is a high-risk corridor due to sanctions, we will:
- Obtain medical invoices from the Lebanese hospital
- Verify the hospital is not sanctions-listed
- Confirm the customer's relationship to the patient
- Document the source of funds
- Monitor future transactions to ensure consistency"
Address Your Specific Risks
Generic programs get rejected. If you operate Pacific corridors, address specific risks like:
- Seasonal remittance patterns (Christmas, cultural obligations)
- Limited banking infrastructure in receiving countries
- Cash-intensive economies
- Family support vs commercial transactions
Show Continuous Improvement
Include review and update procedures: "The Compliance Officer reviews monitoring rules monthly, analysing:
- False positive rates (target <30%)
- Alert investigation times (target <48 hours)
- SMR quality feedback from AUSTRAC
- Emerging typologies from FINTEL Alliance"
Common Pitfalls to Avoid
Copying Generic Templates
AUSTRAC immediately identifies copied templates. Your program must reflect your actual operations. If you don't offer business accounts, don't include business customer procedures. If you only serve three corridors, focus your risk assessment on those specific countries.
Ignoring Technology Limitations
Be honest about your systems. If you use manual transaction monitoring, detail your review processes. Don't claim automated monitoring capabilities you don't have. AUSTRAC prefers well-documented manual processes over fictional automation.
Underestimating Training Requirements
Many programs fail because they propose unrealistic training. If you have five staff, don't commit to monthly two-day training sessions. Instead, propose practical approaches like:
- 15-minute daily huddles on compliance topics
- Monthly 1-hour training sessions
- Quarterly scenario exercises
- Annual full-day compliance workshop
Missing Agent Oversight
If you use agents, your program must detail oversight procedures:
- Agent due diligence before appointment
- Training requirements and records
- Transaction monitoring across agent network
- Audit schedule (risk-based frequency)
- Termination procedures for non-compliance
Template Structure for 2026 AML/CTF Program
Here's a practical template structure that meets AUSTRAC requirements:
1. PROGRAM OVERVIEW
1.1 Business Description
1.2 Designated Services Provided
1.3 Program Approval and Maintenance
1.4 Definitions and Abbreviations
2. ML/TF RISK ASSESSMENT
2.1 Risk Assessment Methodology
2.2 Customer Risk Categories
2.3 Product and Channel Risks
2.4 Geographic/Corridor Risks
2.5 Overall Risk Profile
2.6 Risk Review Schedule
3. CUSTOMER DUE DILIGENCE
3.1 Standard CDD Requirements
3.2 Enhanced CDD Triggers and Procedures
3.3 Simplified CDD (if applicable)
3.4 Beneficial Ownership
3.5 Ongoing CDD and Reviews
3.6 Prohibited Customers
4. TRANSACTION MONITORING
4.1 Monitoring Rules and Parameters
4.2 Alert Investigation Procedures
4.3 Escalation and Decision Making
4.4 System Testing and Tuning
4.5 Manual Review Processes
5. REPORTING OBLIGATIONS
5.1 Suspicious Matter Reports
5.2 Threshold Transaction Reports
5.3 International Funds Transfer Instructions
5.4 Compliance Reports to Board
5.5 Regulatory Correspondence
6. GOVERNANCE AND OVERSIGHT
6.1 Board Responsibilities
6.2 Senior Management Accountability
6.3 AML/CTF Compliance Officer
6.4 Three Lines of Defence
6.5 Independent Review Program
7. TRAINING AND AWARENESS
7.1 Training Needs Assessment
7.2 Role-Based Training Matrix
7.3 Training Delivery Methods
7.4 Competency Assessment
7.5 Training Records
8. RECORD KEEPING
8.1 Retention Requirements
8.2 Storage and Security
8.3 Access Controls
8.4 Production for Authorities
8.5 Disposal Procedures
9. PROGRAM BREACHES AND REMEDIATION
9.1 Breach Identification
9.2 Assessment and Reporting
9.3 Remediation Procedures
9.4 Preventive Measures
9.5 Lessons Learned Process
10. APPENDICES
A. Risk Assessment Methodology
B. CDD Checklist Templates
C. Red Flag Indicators
D. Escalation Contact Lists
E. Regulatory References
Approval Process and Timeline
Board Approval Requirements
Under the 2026 reforms, your board (or equivalent governing body) must formally approve your AML/CTF program before implementation. For sole traders, you must document your approval as the business owner.
Board Approval Checklist:
- Full program reviewed by all board members
- Risk assessment findings understood
- Resource requirements approved
- Compliance Officer appointed with sufficient authority
- Review schedule established (minimum annual)
- Minutes documenting approval decision
AUSTRAC Notification Timeline
While you don't need pre-approval from AUSTRAC, you must:
- Implement your approved program immediately
- Notify AUSTRAC of adoption within 14 days
- Provide a copy upon request (within 3 business days)
- Update AUSTRAC on material changes within 30 days
Living Document Management
Trigger Events for Updates
Your program must be updated within 30 days of:
- New corridor launches
- Product or service changes
- Regulatory amendments
- Significant compliance breaches
- Risk profile changes
- System or process upgrades
Version Control Best Practices
Maintain clear version control:
Version: 2.0
Approval Date: 15 April 2026
Effective Date: 1 May 2026
Next Review: 1 May 2027
Changes: Updated CDD procedures for digital onboarding,
added Pakistan corridor risk assessment,
enhanced PEP screening requirements
Technology Considerations
Integration with Compliance Systems
Your program should reference specific technologies:
- Identity verification providers (e.g., GreenID, IDMatrix)
- Sanctions screening tools (e.g., Dow Jones, Refinitiv)
- Transaction monitoring platforms (e.g., ComplyAdvantage, Fiserv)
- Record-keeping systems (e.g., SharePoint, compliance-specific platforms)
Include fallback procedures for system outages: "If automated sanctions screening is unavailable, manually check against DFAT consolidated list and UN sanctions database before processing any transaction."
API and Reporting Automation
For larger operators, detail your automated reporting:
- AUSTRAC Online API integration for SMRs/TTRs
- Daily batch processing schedules
- Exception handling procedures
- Data quality controls
- Reconciliation processes
Frequently Asked Questions
Do I still need separate Part A and Part B documents under the 2026 rules?
No. The 2026 reforms eliminate the Part A/Part B structure. You now create a single, integrated AML/CTF program that covers all elements previously split between the two parts. This consolidated approach reduces duplication and creates clearer accountability.
What happens if I'm already operating when the new rules take effect?
Existing operators have a 12-month transition period from 31 March 2026 to update their programs. However, you must comply with new requirements immediately where they're more stringent than old rules. AUSTRAC recommends starting your program update at least 3 months before the deadline.
Can I use AUSTRAC's template or do I need to create my own?
While AUSTRAC provides guidance and examples, you must create a program specific to your business. Generic templates get rejected because they don't address your unique risks, corridors, and operations. Use AUSTRAC's guidance as a framework, but customise everything to your circumstances.
How detailed should my transaction monitoring rules be?
Your monitoring rules should be specific enough for staff to apply consistently but flexible enough to adapt to emerging risks. Include exact thresholds (e.g., "3 transactions within 24 hours"), investigation steps, and escalation criteria. Avoid vague statements like "monitor for unusual activity" without defining what constitutes "unusual" for your business.
Taking Action
Writing your AML/CTF program under the 2026 rules requires balancing regulatory compliance with operational reality. Start with an honest risk assessment, build procedures your team can actually follow, and create documentation that demonstrates your commitment to compliance.
Remember that AUSTRAC values practical effectiveness over perfect paperwork. A well-implemented basic program beats an elaborate program that exists only on paper.
For program templates and compliance tools, visit our AML/CTF Program Builder. For updates on regulatory changes, subscribe to our compliance newsletter.
This information is general in nature and does not constitute legal advice. Consult AUSTRAC or a qualified legal professional for advice specific to your situation.



