Operations

Building a Compliance Culture: Staff Training Frameworks for Small MTOs

Editorial Team
14 min read
Building a Compliance Culture: Staff Training Frameworks for Small MTOs

Photo by The Yuri Arcurs Collection

Staff training is a legal requirement under the AML/CTF Act 2006, not an optional extra. Every remittance provider must deliver an AML/CTF risk awareness training program to employees, and AUSTRAC expects you to prove it works — through documented modules, training records, and evidence that your team applies what they learn. For a small money transfer operator (MTO) with a handful of staff, building this from scratch feels daunting. It doesn't need to be.

This guide walks you through designing a practical training framework: onboarding modules for new hires, annual refreshers, how to keep training records that satisfy an AUSTRAC compliance assessment, and how to demonstrate a genuine compliance culture rather than a box-ticking exercise.

Key Takeaways

  • AML/CTF training is mandatory under section 8.1 of the AML/CTF Rules — every reporting entity must have an employee risk awareness training program as part of Part A of its AML/CTF program.
  • Onboarding training must happen before an employee handles designated services — not weeks into the job.
  • Annual refresher training keeps staff current on typologies, red flags, and regulatory changes such as the 2026 AML/CTF reforms.
  • Training records are examined during AUSTRAC assessments — document who was trained, on what, when, and how competence was verified.
  • Compliance culture is evidenced through behaviour, not certificates alone — AUSTRAC looks for staff who escalate suspicious matters and leaders who back them.

Under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, your AML/CTF program has two parts. Part A covers systems and controls to identify, mitigate and manage money laundering and terrorism financing risk. Employee risk awareness training sits squarely within Part A.

The AML/CTF Rules require your training program to ensure staff understand their obligations, the consequences of non-compliance, the type of ML/TF risk your business faces, and how to recognise and respond to that risk. This applies to every reporting entity offering a designated service — including the smallest remittance dealer processing a few dozen transactions a week.

AUSTRAC treats training failures seriously. In enforcement actions and remediation programs, inadequate staff training is a recurring theme. When a frontline officer misses an obvious red flag or fails to lodge a suspicious matter report, the root cause is often a training gap — and that gap becomes your liability.

The practical point: training protects your business. A well-trained team catches suspicious activity early, files accurate reports, and shields you from the reputational and financial damage of a compliance breach.

What AUSTRAC Expects From Your Training Program

AUSTRAC does not prescribe a specific curriculum or number of training hours. Instead, it expects your program to be risk-based and proportionate to your business. A two-person MTO running one corridor faces different risks than a 30-branch operator across multiple high-risk destinations.

Your training program should cover, at minimum:

  • ML/TF and proliferation financing basics — what money laundering, terrorism financing and proliferation financing look like in a remittance context.
  • Your specific ML/TF risk assessment — the corridors, customer types, and channels that expose your business.
  • Customer identification and KYC procedures — how to verify identity and beneficial ownership under the 2026 reforms.
  • Red flags and suspicious activity indicators — structuring, unusual transaction patterns, third-party involvement, and behavioural cues.
  • Reporting obligations — threshold transaction reports (TTRs), international funds transfer instructions (IFTIs), and suspicious matter reports (SMRs), including deadlines.
  • Sanctions screening — DFAT, OFAC and UN list obligations and what to do on a hit.
  • Record-keeping requirements and the tipping-off offence.
  • The 2026 AML/CTF reforms — including the shift to the value transfer chain concept and updated beneficial ownership rules.

AUSTRAC also expects training to be tailored to roles. A frontline agent needs deep knowledge of KYC and red flags. Your AML/CTF Compliance Officer needs the full picture, including reporting mechanics and program governance.

Designing Your Onboarding Training Module

Every new employee who touches a designated service must complete AML/CTF training before they process transactions or handle customers. Onboarding is your first and most important line of defence.

Structure the onboarding module in three layers

Layer 1 — Foundations (all staff). Cover what money laundering and terrorism financing are, why remittance is attractive to criminals, and the legal framework governing your business. Keep it concrete with local examples: a customer splitting a large transfer into several transactions under the AUD 10,000 TTR threshold, or a sender using multiple beneficiaries.

Layer 2 — Role-specific procedures. Teach the actual workflows the employee will use: your customer onboarding process, identity verification tools (including eKYC), your transaction monitoring alerts, and exactly how to escalate a concern. Use your real systems and forms, not generic slides.

Layer 3 — Reporting and escalation. Walk through TTR, IFTI and SMR obligations. Make clear that any staff member can raise a concern, who the AML/CTF Compliance Officer is, and that escalating in good faith carries no penalty — even if the concern turns out to be nothing.

A sample onboarding timeline

DayActivityOwner
Day 1Foundations module + AML/CTF program overviewCompliance Officer
Day 2Role-specific KYC and monitoring walkthroughLine manager
Day 3Reporting, escalation, tipping-off, sanctionsCompliance Officer
Day 4Supervised transaction processingLine manager
Day 5Competency check + sign-offCompliance Officer

Finish onboarding with a competency assessment — a short quiz or scenario exercise. A pass confirms the employee understood the material; a fail means more training before they work unsupervised. Record both the attempt and the outcome.

Annual Refresher Training That Actually Sticks

Onboarding gets staff started. Annual refresher training keeps them sharp and demonstrates ongoing commitment to AUSTRAC. Refreshers should not simply repeat the onboarding deck — that trains complacency, not competence.

Each year, refresh your training to reflect:

  • New typologies and red flags — draw on AUSTRAC financial crime guides, Fintel Alliance intelligence, and your own SMR experience.
  • Regulatory changes — the 2026 AML/CTF reforms, updated IFTI rules, beneficial ownership obligations, and proliferation financing requirements.
  • Lessons from your own business — near-misses, alerts that were mishandled, and feedback from any independent review.
  • Corridor-specific risks — if you have expanded into a higher-risk destination, cover the new exposure.

Use varied delivery methods to hold attention. A 45-minute refresher built around real anonymised case studies works better than an hour of dense regulation. Ask staff to work through a scenario: "A regular customer suddenly sends AUD 9,500 three times in one week to a new beneficiary in a high-risk jurisdiction. What do you do?" Discussion-based training embeds judgment in a way slides never will.

For small teams, you can run refreshers as a facilitated group session, an online module from your AML software provider, or a mix of both. The delivery method matters less than the evidence that learning occurred and was tested.

Keeping Training Records That Survive an AUSTRAC Assessment

During a compliance assessment, AUSTRAC will ask to see your training records. Vague assurances that "everyone did the training" will not satisfy an assessor. You need a documented, auditable trail.

What every training record should capture

  • Employee name and role
  • Training topic and content covered (or module version)
  • Date completed
  • Delivery method (in-person, online, self-study)
  • Assessment result (pass/fail, score)
  • Trainer or facilitator
  • Employee acknowledgement/signature

Maintain a central training register — a spreadsheet works for a small MTO, though a learning management system scales better. The register should show, at a glance, who has completed current training and who is overdue.

Sample training register format

EmployeeRoleOnboarding dateLast refresherNext dueScoreStatus
J. NguyenFrontline agent12 Feb 202512 Feb 202512 Feb 202692%Current
A. KhanCompliance Officer03 Jan 202415 Jan 202615 Jan 202796%Current
L. OseiFrontline agent20 Nov 2025—20 Nov 202688%Current

Retain training records for seven years, consistent with AML/CTF record-keeping obligations. Store copies of the actual training materials used each year too — an assessor may want to see what content staff were exposed to, not just that they attended.

Evidencing a Genuine Compliance Culture

AUSTRAC increasingly looks beyond documents to compliance culture — whether AML/CTF obligations are lived across the business or treated as paperwork. A folder of certificates does not prove culture. Behaviour does.

What a strong compliance culture looks like

Leadership sets the tone. Owners and senior managers reference compliance in decisions, resource the AML/CTF program properly, and never pressure staff to process a questionable transaction to hit revenue targets. AUSTRAC calls this "tone from the top," and it is one of the clearest signals of culture.

Staff escalate without fear. Frontline officers raise concerns knowing they will be supported, not blamed. A rising number of internal escalations is a healthy sign, not a problem — it means training is working.

Compliance is discussed regularly. Brief AML/CTF updates in team meetings, shared alerts about new scams, and open conversation about difficult cases all show a living program.

The Compliance Officer has authority. The AML/CTF Compliance Officer can halt a transaction, decline a customer, and report to senior management directly. Their independence is protected.

How to evidence culture during an assessment

AUSTRAC assessors gather evidence of culture through interviews as much as documents. Prepare by:

  • Keeping minutes of team meetings where AML/CTF topics were discussed.
  • Documenting escalations and how they were handled, including the outcome.
  • Recording management review of the AML/CTF program and any resources approved.
  • Ensuring frontline staff can explain your escalation process in their own words — assessors often ask junior staff directly.

When a frontline agent can describe a real suspicious matter they escalated and what happened next, that single conversation demonstrates more compliance culture than any policy document.

Common Training Mistakes Small MTOs Make

Small operators repeat the same avoidable errors. Watch for these:

  1. Training too late. New staff process transactions before completing training. Fix: no designated service handling until onboarding is signed off.
  2. Generic, off-the-shelf content. Training that never mentions your corridors, systems or risks. Fix: tailor every module to your business.
  3. No competency check. Attendance recorded, understanding never tested. Fix: add a short assessment with a documented result.
  4. Skipping refreshers. Onboarding done once, never revisited. Fix: diarise annual refreshers and track due dates in your register.
  5. Poor records. Verbal training with no paper trail. Fix: log every session in a central register retained for seven years.
  6. Ignoring the Compliance Officer's own training. The person running the program never updates their own knowledge. Fix: the Compliance Officer should complete external professional development annually.

Cost and Resourcing: What a Small MTO Should Budget

Training does not require a large budget. Your main options:

ApproachIndicative annual cost (AUD)Best for
In-house program (self-developed)Staff time onlyVery small MTOs with a capable Compliance Officer
Online AML training modules (per user)100–400 per employeeTeams wanting standardised, tracked content
AML software with built-in trainingBundled with subscriptionMTOs already using compliance software
External facilitated workshop1,500–4,000 per sessionAnnual refreshers, whole-team sessions
Compliance consultant program design2,000–6,000 one-offBuilding a framework from scratch

Many MTOs combine approaches: a consultant designs the framework once, online modules deliver and track ongoing training, and the Compliance Officer runs an annual facilitated session using real case studies. The investment is modest against the cost of an AUSTRAC enforcement action.

Aligning Training With the 2026 AML/CTF Reforms

The 2026 AML/CTF reforms change several obligations your training must reflect. Update your modules to cover the value transfer chain framework replacing designated remittance arrangements, the expanded beneficial ownership verification requirements, and updated IFTI reporting rules.

With Tranche 2 bringing lawyers, accountants and other gatekeepers into the regime, your staff should also understand how due diligence expectations are rising across the sector. Refresh training in the months around each reform milestone so your team applies the new rules from day one, not after a mistake.

Document the fact that you updated training to reflect the reforms — this shows AUSTRAC a responsive, current program.

Putting It All Together: Your Training Framework Checklist

  • Written training program documented within Part A of your AML/CTF program
  • Onboarding module completed before staff handle designated services
  • Role-specific content for frontline, back office, and compliance roles
  • Competency assessment with documented pass/fail results
  • Annual refresher scheduled and tracked for every employee
  • Central training register maintained and up to date
  • Training materials retained for seven years
  • Content updated for 2026 reforms and current typologies
  • Evidence of compliance culture (meeting minutes, escalation logs)
  • Compliance Officer completes annual external professional development

Work through this checklist and you will have a training framework that satisfies your legal obligations and stands up to AUSTRAC scrutiny.

Frequently Asked Questions

Is AML/CTF staff training legally required for small MTOs?

Yes. Under the AML/CTF Act 2006 and the AML/CTF Rules, every reporting entity must include an employee risk awareness training program in Part A of its AML/CTF program. This applies regardless of size — a two-person remittance business has the same core training obligation as a large operator, though the program should be proportionate to its risk.

How often should remittance staff complete AML/CTF training?

Staff must complete training before handling designated services, then refresh at least annually. AUSTRAC expects ongoing training that keeps pace with new typologies and regulatory change, so many MTOs supplement annual refreshers with ad hoc updates when a significant reform or emerging risk arises.

What training records does AUSTRAC want to see during an assessment?

AUSTRAC assessors expect a documented training register showing who was trained, on what content, when, how competence was verified, and the results. Keep the actual training materials used each year too. Retain all records for seven years in line with AML/CTF record-keeping obligations.

How do I prove a compliance culture rather than just completed training?

Evidence culture through behaviour: minutes of meetings where AML/CTF was discussed, logs of staff escalations and their outcomes, records of management reviewing and resourcing the program, and frontline staff who can explain your escalation process in their own words. AUSTRAC assessors often interview junior staff directly to test this.

Can I outsource AML/CTF training for my remittance business?

Yes. You can use online modules, external facilitators or consultants to deliver and design training. However, the legal responsibility remains with your business — you must ensure outsourced training is tailored to your specific risks, tracked in your register, and that your Compliance Officer retains oversight of the program.


This information is general in nature and does not constitute legal advice. Consult AUSTRAC or a qualified legal professional for advice specific to your situation.

Ready to strengthen your compliance foundations? Use our AML/CTF Program tool to build a documented Part A program, and subscribe to our newsletter for updates on the 2026 reforms as they take effect.

AML/CTF trainingcompliance cultureAUSTRACmto-operationsstaff onboarding
Was this guide helpful?