Skip to content

Evidence request lists

AML/CTF Act 2006 (Australia)

Evidence request list. 39 controls, 39 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

AML/CTF Program Requirements

AMLCTF-81
Program Obligation

A reporting entity must have an anti-money laundering and counter-terrorism financing program before providing designated services. The program must be a written document.

Artefacts an auditor will ask for
  • Adopted AML/CTF program
  • Board/senior-management approval
Where this commonly fails
  • No AML/CTF program in place
AMLCTF-82
Part A Compliance

Compliance with Part A of the AML/CTF program covering risk management and operational requirements.

Artefacts an auditor will ask for
  • Part A risk-based systems and controls
  • ML/TF risk methodology
Where this commonly fails
  • Part A does not address ML/TF risk
AMLCTF-84
Standard AML/CTF Program

Standard AML/CTF program applicable where one reporting entity operates independently.

Artefacts an auditor will ask for
  • Standard program (Part A + Part B) for the reporting entity
Where this commonly fails
  • Program not covering required matters
AMLCTF-85
Joint AML/CTF Program

Joint AML/CTF program applicable where two or more reporting entities adopt a joint program.

Artefacts an auditor will ask for
  • Joint program governance for the DBG
Where this commonly fails
  • Joint program lacks member coverage
AMLCTF-PartA-EDD
Employee Due Diligence

Background screening and ongoing monitoring of employees who handle AML/CTF-relevant functions.

Artefacts an auditor will ask for
  • Employee screening & due-diligence program
Where this commonly fails
  • Staff not screened for AML/CTF risk
AMLCTF-PartA-OCDD
Ongoing Customer Due Diligence

Processes to ensure customer information remains up-to-date, including enhanced customer due diligence (ECDD) for high-risk customers.

Artefacts an auditor will ask for
  • OCDD program incl. trigger-based reviews
Where this commonly fails
  • No ongoing CDD
AMLCTF-PartA-Officer
AML/CTF Compliance Officer

Designation of a compliance officer at management level to manage implementation of operational measures.

Artefacts an auditor will ask for
  • AMLCO appointment at management level
Where this commonly fails
  • No designated AMLCO
AMLCTF-PartA-Review
Independent Review

Part A must be regularly independently reviewed to ensure adequacy and effectiveness.

Artefacts an auditor will ask for
  • Independent review reports of Part A effectiveness
Where this commonly fails
  • Part A never independently reviewed
AMLCTF-PartA-RiskAssess
ML/TF Risk Assessment

Part A must include identification, mitigation and management of the money laundering and terrorism financing risks the entity may reasonably face in providing designated services.

Artefacts an auditor will ask for
  • Documented ML/TF risk assessment across customers, products, channels, jurisdictions
Where this commonly fails
  • No ML/TF risk assessment
AMLCTF-PartA-Training
AML/CTF Risk Awareness Training

Training programs for staff on ML/TF risks and obligations.

Artefacts an auditor will ask for
  • Risk-awareness training records
Where this commonly fails
  • Staff untrained on ML/TF risk and obligations
AMLCTF-PartA-TxnMon
Transaction Monitoring

Systems and controls for monitoring customer transactions for unusual or suspicious activity.

Artefacts an auditor will ask for
  • Transaction monitoring system & rules
  • Alert investigation records
Where this commonly fails
  • No transaction monitoring

Confidentiality

AMLCTF-TIPPING
Tipping Off Prohibition

Prohibition on disclosing to the customer or third parties that an SMR has been or may be made.

Artefacts an auditor will ask for
  • Controls preventing disclosure of SMRs / notifiable matters
Where this commonly fails
  • Disclosure that an SMR was made (tipping off)

Customer Identification (KYC)

AMLCTF-34
Customer Identification Obligation

Reporting entities must identify customers before providing designated services (Part 2, s 34).

Artefacts an auditor will ask for
  • Documented ACIP / KYC procedures
  • Customer identity records
Where this commonly fails
  • Customers onboarded without completing ACIP
AMLCTF-35
Identity Verification Standard

Customer identity must be verified using reliable and independent documentation or electronic data sources before providing designated services.

Artefacts an auditor will ask for
  • Reliable, independent verification of identity (documentary/electronic)
Where this commonly fails
  • Identity not verified to the required standard
AMLCTF-PartB-BO
Beneficial Ownership

Identification and verification of beneficial owners of customers.

Artefacts an auditor will ask for
  • Beneficial ownership identification & verification
Where this commonly fails
  • Beneficial owners not identified
AMLCTF-PartB-ECDD
Enhanced Customer Due Diligence

Enhanced CDD must be applied in high-risk scenarios with additional identification, verification and monitoring steps.

Artefacts an auditor will ask for
  • ECDD procedures for high-risk customers / SMR triggers
Where this commonly fails
  • No ECDD for high-risk customers
AMLCTF-PartB-PEP
Politically Exposed Persons

Procedures for identifying customers and beneficial owners who are Politically Exposed Persons (PEPs).

Artefacts an auditor will ask for
  • PEP identification & senior-management approval
  • Source of wealth/funds checks
Where this commonly fails
  • PEPs not identified or escalated
AMLCTF-PartB-RBA
Risk-Based Approach to CDD

Customer due diligence procedures must be based on the level of ML/TF risk that different customers pose.

Artefacts an auditor will ask for
  • Risk-based CDD procedures
Where this commonly fails
  • CDD not risk-based
AMLCTF-PartB-SCDD
Simplified Customer Due Diligence

Simplified CDD may be applied in low-risk scenarios with reduced identification requirements.

Artefacts an auditor will ask for
  • SCDD criteria and approvals
Where this commonly fails
  • Simplified CDD applied to higher-risk customers

Network

AMLCTF-AGENT-OVERSIGHT
Agent Oversight (Remittance/DCE)

Remittance and DCE providers oversee their agents and ensure AML/CTF compliance throughout the network.

Artefacts an auditor will ask for
  • Agent due diligence & oversight program
Where this commonly fails
  • Agents not subject to AML/CTF oversight

Program

AMLCTF-PART-A
AML/CTF Program Part A

Part A identifies, mitigates, and manages money laundering and terrorism financing risks the entity may face.

Artefacts an auditor will ask for
  • Part A of the AML/CTF program
Where this commonly fails
  • Part A missing or incomplete
AMLCTF-PART-B
AML/CTF Program Part B (Customer Due Diligence)

Part B sets out applicable customer identification procedures including verification methods.

Artefacts an auditor will ask for
  • Part B customer due diligence procedures
Where this commonly fails
  • Part B missing or incomplete

Record-Keeping Obligations

AMLCTF-107
General Record-Keeping

General record-keeping obligations for reporting entities under s 107.

Artefacts an auditor will ask for
  • Transaction records retained
Where this commonly fails
  • Transaction records not retained
AMLCTF-108
Customer Identification Records

Records relating to customer identification must be maintained under s 108.

Artefacts an auditor will ask for
  • Customer identification records retained
Where this commonly fails
  • Identification records not retained
AMLCTF-111
Transaction Records

Records relating to designated service transactions must be maintained under s 111.

Artefacts an auditor will ask for
  • EFT instruction records retained
Where this commonly fails
  • EFT records not retained
AMLCTF-114
Electronic Funds Transfer Records

Records relating to electronic funds transfers must be maintained under s 114.

Artefacts an auditor will ask for
  • Records evidencing AML/CTF program adoption and changes
Where this commonly fails
  • Program records not retained
AMLCTF-Penalty
Non-Compliance Penalties

Penalties for non-compliance with AML/CTF obligations up to A$31.3 million per breach for corporations.

Artefacts an auditor will ask for
  • Awareness of civil-penalty exposure for breaches
Where this commonly fails
  • Not applicable as a control objective; enforcement
AMLCTF-Retention
7-Year Retention Period

Most records must be retained for 7 years and be readily accessible if requested by AUSTRAC.

Artefacts an auditor will ask for
  • Retention schedule enforcing 7 years from transaction/relationship end
Where this commonly fails
  • Records destroyed before 7 years

Registration

AMLCTF-ENROL
AUSTRAC Enrolment

Reporting entities must enrol with AUSTRAC within 28 days of commencing designated services.

Artefacts an auditor will ask for
  • AUSTRAC enrolment record
Where this commonly fails
  • Reporting entity not enrolled
AMLCTF-REGISTER
AUSTRAC Registration (Remittance/DCE)

Remittance providers and digital currency exchange providers must register with AUSTRAC in addition to enrolment.

Artefacts an auditor will ask for
  • AUSTRAC registration for remittance/digital-currency exchange
Where this commonly fails
  • Operating remittance/DCE without registration

Reliance

AMLCTF-RELIANCE
Reliance on Third Parties

Reliance arrangements with other reporting entities require written agreements and verification access.

Artefacts an auditor will ask for
  • Reliance arrangements & agreements with the third party
Where this commonly fails
  • Reliance without a compliant arrangement

Reporting Obligations (AML/CTF)

AMLCTF-41
Suspicious Matter Reports (SMRs)

Reporting entities must submit SMRs when suspecting a customer or transaction relates to money laundering, terrorism financing, or other criminal activity. Within 24 hours for terrorism financing; 3 business days for other matters.

Artefacts an auditor will ask for
  • SMR submissions to AUSTRAC within 3/24 business hours
  • Suspicion-detection procedures
Where this commonly fails
  • Suspicious matters not reported within statutory timeframe
AMLCTF-43
Threshold Transaction Reports (TTRs)

Cash transactions of A$10,000 or more (or foreign currency equivalent) must be reported within 10 business days after the transaction date.

Artefacts an auditor will ask for
  • TTR submissions for cash >= AUD 10,000 within 10 business days
Where this commonly fails
  • Threshold transactions not reported
AMLCTF-45
International Funds Transfer Instructions (IFTIs) - Sending

Transfer instructions for funds of any value sent out of Australia must be reported within 10 business days.

Artefacts an auditor will ask for
  • IFTI reports for electronic transfers
Where this commonly fails
  • IFTIs not reported
AMLCTF-46
International Funds Transfer Instructions (IFTIs) - Receiving

Transfer instructions for funds of any value received into Australia must be reported within 10 business days.

Artefacts an auditor will ask for
  • IFTI reports for remittance-arrangement transfers
Where this commonly fails
  • Remittance IFTIs not reported
AMLCTF-47
Annual AML/CTF Compliance Reports

Annual compliance report obligation for all reporting entities, filed between 1 January and 31 March each year covering the previous calendar year.

Artefacts an auditor will ask for
  • Annual AML/CTF compliance report to AUSTRAC
Where this commonly fails
  • Compliance report not lodged
AMLCTF-Structuring
Structuring Offence

It is a criminal offence to structure transactions to avoid threshold reporting requirements (e.g., splitting a $15,000 cash transaction into two below $10,000).

Artefacts an auditor will ask for
  • Detection of structuring patterns
Where this commonly fails
  • Structuring not detected or addressed

Risk Management

AMLCTF-NEW-PRODUCTS
New Product and Channel Risk

Assess AML/CTF risks before launching new products, services, channels, or technologies.

Artefacts an auditor will ask for
  • New-product/channel ML/TF risk assessment before launch
Where this commonly fails
  • New products launched without ML/TF risk assessment

Sanctions

AMLCTF-SANCTIONS
Sanctions Screening

Screen customers and transactions against DFAT consolidated list and UN sanctions to comply with autonomous sanctions.

Artefacts an auditor will ask for
  • Sanctions screening against DFAT consolidated list
Where this commonly fails
  • No sanctions screening
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.