Skip to main content

Build and Review Your AML/CTF Program Under the Current Regime

A current, scope-aware checklist for accounting practices that provide covered professional designated services to build and review their AML/CTF program.

AML CTF compliance program, AUSTRAC compliance program accountants, how to prepare AML 2026, anti-money laundering program guide, AML compliance steps accountants

02/04/2026 7 min read

# Build and Review Your AML/CTF Program Under the Current Regime The expanded AML/CTF regime has been in force since 1 July 2026. It applies to accounting practices when they provide covered professional designated services with an Australian geographic link. If your practice is in scope, use these steps to review the program and controls you operate now. **Source review: 25 August 2026.** Reviewed against AUSTRAC's current reporting-regime, professional designated-services and existing-customer transition guidance. General information only, not legal advice. Your program must reflect the current Act, Rules, guidance, services and risk assessment. ## Step 1: Appoint a Compliance Officer **Current check: confirm governance and accountability** If your practice is a reporting entity, confirm the current compliance-officer requirements and appoint an eligible person with appropriate authority. Responsibilities may include: - Overseeing the development and maintenance of the AML/CTF program - Ensuring staff training is delivered and documented - Acting as the primary point of contact with AUSTRAC - Managing suspicious matter reporting processes - Conducting or coordinating the annual program review ### Who Should It Be? In a solo practice, the principal is the compliance officer by default. In a larger practice: - Choose someone with authority to make decisions and enforce compliance - The person should have (or be willing to gain) knowledge of AML/CTF obligations - Consider the compliance officer role when hiring or allocating responsibilities - The role can be combined with other duties but must have adequate time allocated ### What to Document Create a formal compliance officer appointment document that includes: - Name and position of the compliance officer - Date of appointment - Scope of responsibilities - Reporting line (to partners or board) - Signature of the appointee and a senior partner Keep the appointment and responsibilities documented as part of your governance file. ## Step 2: Conduct an ML/TF Risk Assessment **Current check: keep the risk assessment up to date** Before you can build your program, you need to understand your specific risks. A risk assessment evaluates the money laundering and terrorism financing (ML/TF) risks relevant to your practice. ### What to Assess **Client risk factors:** - What types of clients do you serve? (individuals, companies, trusts, SMSFs) - Do any clients have complex or opaque ownership structures? - Do you serve clients from or connected to high-risk jurisdictions? - What is the typical source of funds/wealth for your client base? - Do any clients have political connections (PEPs)? **Service/product risk factors:** - Which designated services do you provide? - Do you manage client money, securities, or other assets? - Do you create or manage legal entities (companies, trusts)? - Do you handle large or unusual transactions? **Delivery channel risk factors:** - Do you meet clients face-to-face or operate remotely? - Do clients engage through intermediaries or third parties? - How do clients pay you (cash, electronic transfer, crypto)? **Geographic risk factors:** - Where are your clients based? - Do any client transactions involve high-risk countries? - Do you have international clients or cross-border service delivery? ### Risk Assessment Output Your assessment should produce: 1. **A risk matrix** mapping each risk factor to a rating (low, medium, high) 2. **An overall practice risk rating** based on the aggregate assessment 3. **Specific high-risk areas** that require enhanced controls 4. **Documented rationale** for each risk rating Keep the assessment proportionate to your practice size. A solo practitioner serving 30 individual tax clients has a very different risk profile to a mid-tier firm providing corporate advisory services to international clients. ## Step 3: Develop Your AML/CTF Program **Current check: review the documented program** Your AML/CTF program documents how your practice addresses its applicable obligations. Build it against the current Act, Rules and AUSTRAC guidance, and tailor it to the covered services and risks you actually have. ### Risk assessment and customer controls **1. Customer identification and verification procedures:** - How you will identify clients ([see our complete CDD guide](/resources/blog/kyc-customer-due-diligence-guide-accounting-firms)) - What documents or electronic methods you will use for verification - Procedures for individuals, companies, trusts, and SMSFs - When to apply simplified, standard, or enhanced CDD **2. Beneficial owner identification:** - How you will trace ownership through layers of entities - The 25% ownership threshold for identification - Procedures when beneficial owners cannot be identified - Documentation requirements **3. Ongoing customer due diligence:** - Frequency of CDD reviews by risk level - Triggers for ad-hoc reviews (e.g., change in ownership, unusual transactions) - Process for updating client information - Re-screening procedures for PEP and sanctions lists **4. Transaction monitoring:** - How you will monitor client transactions for suspicious activity - Red flag indicators specific to your services - Escalation procedures when suspicious activity is detected **5. Reporting procedures:** - How and when to file Suspicious Matter Reports (SMRs) - Process for Threshold Transaction Reports (TTRs) if applicable - Record-keeping for all reports filed - Tipping off protections **6. Record-keeping:** - What records to retain - Retention periods (7 years minimum) - Storage and security requirements - Retrieval procedures for audits ### Governance and people controls **1. Employee due diligence:** - Pre-employment screening procedures - Ongoing monitoring of employee conduct - Procedures for employees with access to sensitive client information **2. Training program:** - Initial and ongoing AML/CTF training for the roles identified by your program - Annual refresher training - Role-specific training for compliance officer and front-line staff - Training records and documentation **3. Whistleblower protections:** - Internal reporting channels for staff who suspect ML/TF - Protection from retaliation for good-faith reports - Escalation procedures ### Program Review Set a review and independent-evaluation cycle that meets the current requirements for your practice, including review: - On the cycle required by the current framework and your program - Whenever there is a material change in your practice (new services, new client types, regulatory changes) - After a compliance incident or near-miss - Document each review with fin

Ready to transform your practice?

Built and run every day by Tax7, an Australian accounting practice. Fedix prepares the work - you review and sign.

Request a Practice Review
dings and any changes made ## Step 4: Implement CDD Procedures **Current check: test day-to-day procedures** With your program written, implement the actual procedures that will run day-to-day. ### New Client Onboarding Build a standard onboarding workflow: 1. **Confirm scope and collect information** -- identify the covered service and use a form tailored to the applicable CDD measures 2. **Verify identity** -- use electronic verification (preferred) or document-based verification 3. **Screen for PEPs and sanctions** -- automated screening against DFAT, UN, and other lists 4. **Assess risk** -- apply your risk matrix to assign a risk rating 5. **Apply appropriate CDD level** -- simplified, standard, or enhanced based on risk 6. **Document and store** -- save all verification results, risk assessment, and supporting documents 7. **Approve the relationship** -- senior management approval required for high-risk and PEP clients ### Technology Selection Choose proportionate KYC/AML tooling for the workflow you have documented. The law does not require Fedix or any particular software: - **Electronic identity verification** -- automates ID checks against government databases - **PEP and sanctions screening** -- automates screening against watchlists - **Risk scoring** -- automates risk categorisation based on your assessment criteria - **Record management** -- stores all CDD records with full audit trail Fedix assists with identity-verification workflow, DFAT Consolidated List screening, AI-assisted political-exposure indicators (not a licensed PEP database), draft risk ratings and records. The practice reviews and decides. Your first 10 verifications are free, then $2.90+gst per verification, with no monthly fees. [See the defined feature scope](/features/kyc-aml). ### Existing Client Retrospective Transition rules for existing customers are conditional. Risk and specified trigger events can affect when initial CDD is required, so use AUSTRAC's current guidance rather than applying one universal date: - Prioritise high-risk clients (complex structures, PEP connections, high-value services) - Use annual tax return meetings as a natural touchpoint for CDD collection - Process 10-20% of existing clients per month to spread the workload ## Step 5: Set Up Ongoing Monitoring and Reporting **Current check: operate and monitor the controls** An AML/CTF program is not a one-time project. Operate the ongoing controls that apply to your covered services and customer relationships. ### Transaction and Activity Monitoring Establish processes to: - Review client transactions for consistency with their profile and risk rating - Identify unusual or suspicious patterns (e.g., round-dollar transfers, structuring, third-party payments) - Flag transactions that do not match the stated purpose of the business relationship ### Sanctions List Monitoring Set a sanctions-control process that matches your obligations and risk assessment. It may include: - Re-screen your client base when the list is updated - Decide how list updates are monitored and when re-screening is triggered - Have a process for handling new matches against existing clients ### Periodic CDD Reviews | Client Risk Level | Review Frequency | Actions | |-------------------|-----------------|---------| | Lower | Set by your program and applicable trigger rules | Confirm the information and measures the current Rules require | | Medium | Risk-based and event-driven | Update information and re-screen where your procedure requires it | | Higher | More frequent or event-driven as required | Apply enhanced measures and approvals where the current framework requires them | ### Reporting to AUSTRAC Ensure your practice can: - File SMRs within the required timeframes (24 hours for terrorism, 3 business days for others) - File TTRs for cash transactions of $10,000 or more - Submit annual compliance reports - Respond to AUSTRAC information requests ### Record Keeping Keep the records required by the current law and your program. Many AML/CTF records have a seven-year retention period, but the start point depends on the record type. Confirm the current rule rather than applying one disposal date to every record. ## Bonus: Staff Training Requirements Identify the roles that require AML/CTF training under your current program and make the content proportionate to their work. ### Initial and role-change training Cover these topics: - Overview of the AML/CTF Act and Tranche 2 reforms - Your practice's AML/CTF program and procedures - How to identify and verify clients - Red flags for money laundering and terrorism financing - How to escalate suspicions internally - Tipping off prohibition and penalties - Record-keeping requirements ### Ongoing Training - Ongoing refresher training on the cycle and trigger events set by your program - Ad-hoc training when regulations or procedures change - Role-specific training for new hires before they begin handling designated services - Document all training with dates, topics, attendees, and materials ## Current-State Review Cycle | Review point | Milestones | |--------------|------------| | **Scope** | Confirm which services are covered and have the required Australian geographic link. | | **Customers** | Apply current initial CDD rules to new customers and conditional transition rules to existing customers. | | **Controls** | Test procedures, train relevant staff, verify records and escalate exceptions. | | **Change** | Reassess when services, customer risk, law or AUSTRAC guidance changes. | ## How Fedix Assists the Workflow Building and operating an AML/CTF program remains the practice's responsibility. Fedix assists with defined workflow steps: - **Electronic identity-verification workflow** -- collect and review verification results in one place - **DFAT sanctions screening and political-exposure indicators** -- indicators are not a licensed PEP database - **Draft risk ratings** -- the practice reviews, changes and approves the rating - **Defined ongoing monitoring** -- re-screening against the supported DFAT list when it changes - **Exportable workflow documentation** -- the practice remains responsible for completeness and legal retention periods - **$2.90+gst per verification** -- first 10 free, volume tiers down to $1.50, predictable costs with no monthly commitment Your practice sets the program, reviews the outputs and makes every decision. Fedix supplies workflow tools; it is not an AML/CTF adviser and does not assume the reporting entity's obligations. [Start building your compliance program with Fedix](/contact) or [learn more about our KYC/AML features](/features/kyc-aml).

Related Articles

Stay Updated

Get tips, updates, and industry insights