AML/CTF Act 2006 (Australia)
Evidence request list. 39 controls, 39 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
AML/CTF Program Requirements
A reporting entity must have an anti-money laundering and counter-terrorism financing program before providing designated services. The program must be a written document.
- Adopted AML/CTF program
- Board/senior-management approval
- No AML/CTF program in place
Compliance with Part A of the AML/CTF program covering risk management and operational requirements.
- Part A risk-based systems and controls
- ML/TF risk methodology
- Part A does not address ML/TF risk
Standard AML/CTF program applicable where one reporting entity operates independently.
- Standard program (Part A + Part B) for the reporting entity
- Program not covering required matters
Joint AML/CTF program applicable where two or more reporting entities adopt a joint program.
- Joint program governance for the DBG
- Joint program lacks member coverage
Background screening and ongoing monitoring of employees who handle AML/CTF-relevant functions.
- Employee screening & due-diligence program
- Staff not screened for AML/CTF risk
Processes to ensure customer information remains up-to-date, including enhanced customer due diligence (ECDD) for high-risk customers.
- OCDD program incl. trigger-based reviews
- No ongoing CDD
Designation of a compliance officer at management level to manage implementation of operational measures.
- AMLCO appointment at management level
- No designated AMLCO
Part A must be regularly independently reviewed to ensure adequacy and effectiveness.
- Independent review reports of Part A effectiveness
- Part A never independently reviewed
Part A must include identification, mitigation and management of the money laundering and terrorism financing risks the entity may reasonably face in providing designated services.
- Documented ML/TF risk assessment across customers, products, channels, jurisdictions
- No ML/TF risk assessment
Training programs for staff on ML/TF risks and obligations.
- Risk-awareness training records
- Staff untrained on ML/TF risk and obligations
Systems and controls for monitoring customer transactions for unusual or suspicious activity.
- Transaction monitoring system & rules
- Alert investigation records
- No transaction monitoring
Confidentiality
Prohibition on disclosing to the customer or third parties that an SMR has been or may be made.
- Controls preventing disclosure of SMRs / notifiable matters
- Disclosure that an SMR was made (tipping off)
Customer Identification (KYC)
Reporting entities must identify customers before providing designated services (Part 2, s 34).
- Documented ACIP / KYC procedures
- Customer identity records
- Customers onboarded without completing ACIP
Customer identity must be verified using reliable and independent documentation or electronic data sources before providing designated services.
- Reliable, independent verification of identity (documentary/electronic)
- Identity not verified to the required standard
Identification and verification of beneficial owners of customers.
- Beneficial ownership identification & verification
- Beneficial owners not identified
Enhanced CDD must be applied in high-risk scenarios with additional identification, verification and monitoring steps.
- ECDD procedures for high-risk customers / SMR triggers
- No ECDD for high-risk customers
Procedures for identifying customers and beneficial owners who are Politically Exposed Persons (PEPs).
- PEP identification & senior-management approval
- Source of wealth/funds checks
- PEPs not identified or escalated
Customer due diligence procedures must be based on the level of ML/TF risk that different customers pose.
- Risk-based CDD procedures
- CDD not risk-based
Simplified CDD may be applied in low-risk scenarios with reduced identification requirements.
- SCDD criteria and approvals
- Simplified CDD applied to higher-risk customers
Network
Remittance and DCE providers oversee their agents and ensure AML/CTF compliance throughout the network.
- Agent due diligence & oversight program
- Agents not subject to AML/CTF oversight
Program
Part A identifies, mitigates, and manages money laundering and terrorism financing risks the entity may face.
- Part A of the AML/CTF program
- Part A missing or incomplete
Part B sets out applicable customer identification procedures including verification methods.
- Part B customer due diligence procedures
- Part B missing or incomplete
Record-Keeping Obligations
General record-keeping obligations for reporting entities under s 107.
- Transaction records retained
- Transaction records not retained
Records relating to customer identification must be maintained under s 108.
- Customer identification records retained
- Identification records not retained
Records relating to designated service transactions must be maintained under s 111.
- EFT instruction records retained
- EFT records not retained
Records relating to electronic funds transfers must be maintained under s 114.
- Records evidencing AML/CTF program adoption and changes
- Program records not retained
Penalties for non-compliance with AML/CTF obligations up to A$31.3 million per breach for corporations.
- Awareness of civil-penalty exposure for breaches
- Not applicable as a control objective; enforcement
Most records must be retained for 7 years and be readily accessible if requested by AUSTRAC.
- Retention schedule enforcing 7 years from transaction/relationship end
- Records destroyed before 7 years
Registration
Reporting entities must enrol with AUSTRAC within 28 days of commencing designated services.
- AUSTRAC enrolment record
- Reporting entity not enrolled
Remittance providers and digital currency exchange providers must register with AUSTRAC in addition to enrolment.
- AUSTRAC registration for remittance/digital-currency exchange
- Operating remittance/DCE without registration
Reliance
Reliance arrangements with other reporting entities require written agreements and verification access.
- Reliance arrangements & agreements with the third party
- Reliance without a compliant arrangement
Reporting Obligations (AML/CTF)
Reporting entities must submit SMRs when suspecting a customer or transaction relates to money laundering, terrorism financing, or other criminal activity. Within 24 hours for terrorism financing; 3 business days for other matters.
- SMR submissions to AUSTRAC within 3/24 business hours
- Suspicion-detection procedures
- Suspicious matters not reported within statutory timeframe
Cash transactions of A$10,000 or more (or foreign currency equivalent) must be reported within 10 business days after the transaction date.
- TTR submissions for cash >= AUD 10,000 within 10 business days
- Threshold transactions not reported
Transfer instructions for funds of any value sent out of Australia must be reported within 10 business days.
- IFTI reports for electronic transfers
- IFTIs not reported
Transfer instructions for funds of any value received into Australia must be reported within 10 business days.
- IFTI reports for remittance-arrangement transfers
- Remittance IFTIs not reported
Annual compliance report obligation for all reporting entities, filed between 1 January and 31 March each year covering the previous calendar year.
- Annual AML/CTF compliance report to AUSTRAC
- Compliance report not lodged
It is a criminal offence to structure transactions to avoid threshold reporting requirements (e.g., splitting a $15,000 cash transaction into two below $10,000).
- Detection of structuring patterns
- Structuring not detected or addressed
Risk Management
Assess AML/CTF risks before launching new products, services, channels, or technologies.
- New-product/channel ML/TF risk assessment before launch
- New products launched without ML/TF risk assessment
Sanctions
Screen customers and transactions against DFAT consolidated list and UN sanctions to comply with autonomous sanctions.
- Sanctions screening against DFAT consolidated list
- No sanctions screening
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.