
Photo by olgamih125
AUSTRAC can assess your remittance business at any time — and preparation is the difference between a routine review and an enforcement referral. To prepare for an AUSTRAC compliance assessment, you need a current AML/CTF program, documented risk assessment, evidence of ongoing customer due diligence, a clean reporting history for IFTIs and threshold transactions, and a compliance officer who can produce records on demand. Assessors want proof that your program works in practice, not just on paper.
Most small operators fail assessments not because they lack a program, but because they cannot demonstrate it is applied consistently. A policy document sitting in a drawer counts for nothing if your transaction monitoring alerts go uninvestigated or your board never reviews the program. This checklist walks you through exactly what AUSTRAC assessors look for, how to organise your documentation, the gaps that trip up small MTOs, and how to respond if AUSTRAC issues a formal notice.
Key Takeaways
- AUSTRAC assesses reporting entities through desk-based reviews, on-site examinations, and targeted campaigns — you may receive as little as a few days' notice.
- Assessors test whether your AML/CTF program operates in practice, checking that risk assessments, customer due diligence, transaction monitoring, and reporting all work together.
- The most common small-operator gaps are stale risk assessments, undocumented board oversight, incomplete customer records, and weak transaction monitoring evidence.
- Organise a single evidence pack covering governance, KYC files, reporting logs, training records, and independent review reports before any assessment begins.
- If AUSTRAC issues a formal notice under section 167 of the AML/CTF Act 2006, respond within the deadline, provide exactly what is requested, and seek legal advice for anything beyond a routine information request.
Why AUSTRAC Assesses Remittance Providers
AUSTRAC supervises more than 5,100 registered remittance providers across Australia, and the remittance sector is treated as higher risk because of its exposure to cross-border flows, cash handling, and third-party funding. As the AML/CTF regulator, AUSTRAC uses compliance assessments to confirm that reporting entities meet their obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 and the associated Rules.
An assessment is not automatically a sign of suspicion. AUSTRAC selects entities through risk-based targeting, industry campaigns, intelligence referrals, and random sampling. A spike in your reporting volume, a suspicious matter report referral, a complaint, or simply operating in a high-risk corridor can put you on the radar.
The outcome matters. A clean assessment reinforces your standing and your banking relationships. A poor one can lead to remedial directions, enforceable undertakings, civil penalties, or — in serious cases — cancellation of your registration. Preparation protects both your licence and your bank account.
The Three Types of AUSTRAC Assessment
Understanding the format helps you prepare the right evidence. AUSTRAC uses several assessment approaches, and the depth of scrutiny varies.
| Assessment type | What it involves | Typical notice period | Depth |
|---|---|---|---|
| Desk-based review | AUSTRAC requests documents and answers to written questions | 1–4 weeks | Moderate — document-focused |
| On-site examination | Assessors visit your premises, interview staff, inspect records and systems | 2–4 weeks | Deep — tests practice, not just policy |
| Campaign or thematic review | Sector-wide focus on one issue (e.g. IFTI accuracy, agent oversight) | Varies | Narrow but detailed |
| Follow-up assessment | Checks remediation after a prior finding | Varies | Targeted at specific gaps |
On-site examinations are the most demanding. Assessors will ask your compliance officer to walk through a live transaction, explain why a monitoring alert was or was not escalated, and produce the relevant customer file. If your systems and records support that story cleanly, you pass. If the narrative falls apart under questioning, expect findings.
What AUSTRAC Assessors Look For
Assessors test the whole compliance lifecycle, not isolated documents. They want to see that your AML/CTF program is current, tailored to your business, and genuinely applied. The following areas form the backbone of nearly every assessment.
1. Enrolment and Registration Status
Assessors first confirm your registration is current and accurate. Your details on the Remittance Sector Register must match your actual operations — business name, key personnel, agents, and the designated services you provide. If you added a new agent or changed your director six months ago without notifying AUSTRAC, that is an immediate finding.
2. A Current, Tailored AML/CTF Program
Your AML/CTF program must reflect the business you actually run today. Assessors compare your program against your operations: the corridors you serve, your customer types, your delivery channels, and your funding methods. A generic template downloaded years ago and never updated is one of the most common red flags.
Under the 2026 AML/CTF reforms that took effect on 31 March 2026, the previous Part A / Part B structure was consolidated into a single program built around the AML/CTF policies concept. Assessors will expect your program to reflect the current Rules, including your documented money laundering, terrorism financing, and proliferation financing risk assessment.
3. A Documented and Current Risk Assessment
Your risk assessment is the foundation of everything else. Assessors check that it is written down, dated, reviewed regularly, and actually informs your controls. They look for evidence that you have assessed risk across the four required factors: customer types, products and services, delivery channels, and the countries you deal with.
A stale risk assessment — one that predates a major change in your corridors or customer base — signals that your controls may no longer match your risk. Review and re-date your risk assessment at least annually and after any material change.
4. Customer Due Diligence in Practice
This is where on-site assessments most often expose gaps. Assessors pull a sample of customer files and check that you collected and verified the required KYC information before providing the designated service. They test:
- Identity collection and verification for individuals and entities
- Beneficial ownership identification for company and trust customers
- Politically exposed person (PEP) screening
- Sanctions screening against the DFAT Consolidated List and relevant lists
- Enhanced due diligence where risk is elevated
- Ongoing due diligence and record currency
Missing verification documents, unrecorded beneficial owners, and no evidence of sanctions screening are frequent findings in small-operator reviews.
5. Transaction Monitoring That Works
A transaction monitoring program that generates alerts nobody investigates is worse than none — it proves you knew and did nothing. Assessors ask to see your monitoring rules, a log of alerts, and the investigation outcomes. They want to see the audit trail from alert to decision to escalation or dismissal, with reasons recorded.
Small MTOs relying on manual monitoring must document their process clearly. Show which transactions you review, against what criteria, how often, and who signs off.
6. Accurate and Timely Reporting
Assessors reconcile your reporting against your transaction data. They check that you submitted:
- International Funds Transfer Instructions (IFTIs) — now reported under the IVTS framework for many remitters — within 10 business days
- Threshold Transaction Reports (TTRs) for cash transactions of AUD 10,000 or more, within 10 business days
- Suspicious Matter Reports (SMRs) within 3 business days (24 hours for terrorism financing)
- Your annual compliance report by the deadline
Late, missing, or inaccurate reports are among the most heavily scrutinised areas. Assessors may compare a sample of your transactions to submitted reports to test completeness.
7. Governance, Oversight, and the Compliance Officer
AUSTRAC expects senior management or the board to take real ownership of AML/CTF compliance. Assessors look for meeting minutes, sign-offs, and evidence that leadership reviews the program and receives compliance reporting. A nominated AML/CTF compliance officer must be identifiable, appropriately senior, and genuinely responsible.
8. Employee Due Diligence and Training
Your staff must be screened before appointment to roles with AML/CTF responsibilities, and trained on their obligations. Assessors ask for your training records, the training content, and the dates each staff member completed it. "We tell them informally" is not an acceptable answer.
9. Independent Review
Your program must be independently reviewed at appropriate intervals. Assessors ask for the most recent independent review report, its findings, and evidence that you acted on recommendations. A review that flagged issues you never remediated is a compounding finding.
The AUSTRAC Readiness Checklist
Use this checklist to build your evidence pack before any assessment arrives. Aim to keep everything in a single, well-indexed location so you can produce records within hours, not days.
Governance and program
- Current AML/CTF program reflecting 2026 Rules, dated and version-controlled
- Documented ML/TF/PF risk assessment, reviewed within the last 12 months
- Board or senior management approval and oversight minutes
- Named AML/CTF compliance officer with a documented role description
Registration and enrolment
- Current registration on the Remittance Sector Register
- All key personnel, agents, and services accurately listed
- Records of any changes notified to AUSTRAC within required timeframes
Customer due diligence
- Sample customer files with complete KYC and verification records
- Beneficial ownership records for entity customers
- Evidence of PEP and sanctions screening at onboarding and ongoing
- Enhanced due diligence files for high-risk customers
Monitoring and reporting
- Transaction monitoring rules and alert investigation logs
- IFTI/IVTS submission records and reconciliation to transactions
- TTR and SMR logs with submission timestamps
- Most recent annual compliance report and lodgement confirmation
People and assurance
- Employee due diligence and screening records
- AML/CTF training records with dates and content
- Most recent independent review report and remediation evidence
- Agent oversight records if you operate under a remittance network
If you can tick every box with a document you could hand over today, you are assessment-ready. Any gap is a task to close now — not when the notice arrives.
Common Gaps Found in Small Operator Assessments
AUSTRAC's supervisory experience with small remitters surfaces the same weaknesses repeatedly. Knowing them lets you self-correct before an assessor finds them.
Stale or generic programs. Many small operators adopt a template and never tailor it. Assessors immediately notice when a program describes services you do not offer or omits corridors you actually serve.
Risk assessment disconnected from controls. A risk assessment that rates certain corridors as high-risk but applies identical controls to every transaction shows the assessment is decorative, not operational.
Incomplete customer verification. Missing identity documents, unverified beneficial owners, and files that lack a record of when and how identity was verified are pervasive findings.
Monitoring without evidence. Operators say they monitor transactions but cannot produce alert logs or investigation records. Without documentation, AUSTRAC treats it as if no monitoring occurred.
Reporting gaps. Late IFTIs and TTRs, or transactions that should have triggered a report but did not, are common — and easy for assessors to detect by reconciliation.
No board oversight trail. Sole operators and small teams often skip governance documentation entirely, leaving no evidence that anyone reviews or approves the program.
Weak agent oversight. Businesses operating as a remittance network provider frequently cannot demonstrate they supervise their affiliates' compliance, which is a direct obligation, not an optional extra.
How to Organise Your Documentation
Assessors judge your compliance partly by how quickly and cleanly you produce records. Disorganised responses suggest disorganised compliance.
Build a single compliance evidence pack, indexed to mirror the checklist above. Store it securely, keep it current, and assign responsibility for maintaining it to your compliance officer. When a request arrives, you should be able to map each item AUSTRAC asks for to a folder you already maintain.
Keep records for the periods the AML/CTF Act requires — generally seven years for customer identification and transaction records. Assessors may ask for historical files, so retention discipline matters as much as current documentation.
Run an internal mock assessment annually. Have someone independent of day-to-day operations pull a customer sample, trace a transaction from monitoring to reporting, and test whether your evidence holds together. This rehearsal reveals gaps while you still have time to fix them.
How to Respond if AUSTRAC Issues a Formal Notice
AUSTRAC has broad information-gathering powers under the AML/CTF Act 2006. It can request documents and information through a notice under section 167, require you to appear and answer questions, and appoint external auditors under section 162. Receiving a notice is serious, but a measured response protects your position.
Read the notice carefully. Identify exactly what is requested, the legal basis, the deadline, and the format required. Notices are specific — provide precisely what is asked for, nothing less and, generally, nothing more.
Meet the deadline. Failing to comply with a notice is itself a breach that can attract penalties. If you genuinely cannot meet the timeframe, contact AUSTRAC before the deadline to request an extension rather than missing it silently.
Preserve records. Do not alter, delete, or backdate anything. Provide records as they exist. Attempting to fix a file after a notice arrives compounds the original problem into misconduct.
Seek legal advice for anything beyond routine. For standard document requests, your compliance officer can usually respond. For enforceable undertakings, remedial directions, examination notices, or anything suggesting an investigation, engage a lawyer experienced in AML/CTF matters before you respond.
Cooperate and document. AUSTRAC treats cooperation as a mitigating factor. Keep a record of every communication, what you provided, and when. A transparent, organised response signals a well-run business even where gaps exist.
If an assessment identifies deficiencies, AUSTRAC often issues findings with a remediation timeframe rather than immediate penalties for good-faith operators. Treat remediation as a priority — a follow-up assessment will check whether you delivered.
Frequently Asked Questions
How much notice does AUSTRAC give before a compliance assessment?
Notice varies by assessment type. Desk-based reviews may give one to four weeks, while on-site examinations typically allow two to four weeks to prepare records and arrange staff availability. AUSTRAC can also make short-notice or targeted requests, so the safest approach is to stay assessment-ready at all times rather than scrambling when a notice arrives.
What happens if AUSTRAC finds gaps in my AML/CTF compliance?
Outcomes range from a written finding with a remediation timeframe through to remedial directions, enforceable undertakings, civil penalties, and registration cancellation in serious cases. For cooperative operators with good-faith gaps, AUSTRAC often requires remediation and conducts a follow-up assessment. Serious or systemic failures — particularly reporting failures or no functioning program — attract stronger enforcement.
Do small remittance operators face the same assessment standards as large ones?
The obligations are the same, but AUSTRAC applies them proportionately to your risk and size. A small operator is not expected to run an enterprise monitoring system, but must still demonstrate a tailored program, documented risk assessment, working customer due diligence, and accurate reporting. "We are too small to comply" is never an accepted defence.
How often should I review my AML/CTF program to stay assessment-ready?
Review your risk assessment and program at least annually, and after any material change to your business — new corridors, new agents, new products, new funding methods, or regulatory changes such as the 2026 reforms. Combine annual reviews with an internal mock assessment and act on independent review recommendations promptly.
Can I refuse to provide documents requested in an AUSTRAC notice?
No. A notice issued under the AML/CTF Act 2006 carries legal force, and failing to comply is a breach that can attract penalties. If you believe a request is unclear, unreasonable, or captures legally privileged material, seek legal advice and raise the issue with AUSTRAC before the deadline — do not simply ignore or refuse the notice.
Stay Assessment-Ready Year-Round
The operators who pass AUSTRAC assessments cleanly are the ones who treat compliance as continuous, not reactive. A current program, a live risk assessment, complete customer files, disciplined reporting, and a documented governance trail turn an assessment from a threat into a routine confirmation that your business runs well.
Start by pressure-testing your program against the 2026 Rules using our AML/CTF program builder, and review your corridor exposure with our corridor guides to confirm your risk assessment reflects where you actually send money. For ongoing regulatory updates that affect what assessors look for, subscribe to our newsletter.
This information is general in nature and does not constitute legal advice. Consult AUSTRAC or a qualified legal professional for advice specific to your situation.

