Back to Blog
AML & Compliance

What goes in an AML/CTF program: a small business guide

Anton
What goes in an AML/CTF program: a small business guide

An AML/CTF program is a document that says how your business stops itself being used to move dirty money. AUSTRAC doesn't publish a fill-in-the-blanks form, which is why so many small firms end up either paying thousands for a consultant or downloading a template that reads like it belongs to a bank.

Neither is necessary. Here's what actually goes in one, and how to write a version that's honest about your business and short enough that your team will read it.

The two halves

Every program does two jobs:

Part A — identify and manage risk. How you work out where your exposure is, and what you do about it. Governance, training, oversight, reporting, record-keeping, independent review.

Part B — know your customer. How you identify and verify customers before you serve them, how you handle entities and beneficial owners, and how you monitor the relationship afterwards.

The reforms restructure some of this language, but the substance is the same. Risk, then controls, then customers.

What has to be in it

1. Business and services

What you do, which of your services are designated services, where you operate, and how you deliver — face-to-face, online, through intermediaries. Two paragraphs, but they scope everything after.

2. Risk assessment

The heart of it. Four risk dimensions:

  • Customer risk — who your clients are. Individuals or entities, local or offshore, straightforward or layered structures, any politically exposed persons.

  • Service risk — which of your services could be misused, and how.

  • Country risk — jurisdictions you deal with, including where clients' funds or owners come from.

  • Channel risk — face-to-face is lower risk than fully remote onboarding.

For each, rate it and say why. The "why" is what makes it yours instead of a template's.

3. Governance

Who's accountable. Name the AML/CTF compliance officer. State who approved the program and when. In a small firm this is the owner, and that's fine — but it must be written.

4. Customer due diligence

Your actual rules. What you collect for individuals, what you collect for companies and trusts, how you get to beneficial owners, when simplified is allowed and when enhanced is mandatory, and what enhanced actually means in your business (source of funds, senior approval, closer monitoring).

Be specific. "We apply a risk-based approach" is not a rule. "Any customer with beneficial ownership outside Australia is rated enhanced and requires the compliance officer's sign-off before engagement" is.

5. Ongoing monitoring

How you keep watching after onboarding. What triggers a re-check, what unusual activity looks like in your business, and who reviews it.

6. Reporting

Suspicious matter reports — who identifies, who decides, who submits, and the timeframe. Threshold transaction reports if you handle large cash. And the tipping-off rule: you don't tell the customer.

7. Staff training and screening

What new staff are told, what everyone gets refreshed on annually, and how you record that it happened. Plus screening for roles with compliance responsibility.

8. Record-keeping

What you keep, where, in what format, and for how long — seven years after the relationship ends. Name the system. "Client files" isn't a system.

9. Independent review

Periodic review by someone who didn't write or run the program. For a small firm this can be an external adviser or another partner, and it should be proportionate to your size.

How long should it be?

For a small professional services firm: fifteen to thirty pages, including the risk assessment. Shorter than that and you've probably skipped the specifics. Much longer and it's a bank's program with your name on the front, and nobody in your office will ever open it.

The test isn't length. It's whether a new staff member could read it and know what to do on Monday.

The four ways programs fail

Generic risk assessment. Copied risk ratings that don't match the actual client base. First thing a reviewer notices.

Rules nobody follows. The program says two forms of ID; the team collects one. The gap between the written and the actual is the finding.

No evidence. The controls run but nothing is recorded, so there's no way to show it. Undocumented compliance is indistinguishable from none.

Set and forgotten. Written in 2026, never updated, still describing services you stopped offering. The program is supposed to change when the business does.

A practical way to write it

  1. Start with the risk assessment, not the program. It forces the thinking and everything else follows from it.

  2. Describe what you already do, then fix the gaps. Most firms already verify clients — you're formalising, not inventing.

  3. Write the controls you'll actually run. A weaker control you follow beats a stronger one you don't.

  4. Get someone else to read it. If they can't tell what to do from it, rewrite that section.

  5. Diarise a review. Annually, or whenever your services, clients or systems change.

Shortcut

Our free AML Compliance Pack generator asks you a series of questions about your business — services, client types, jurisdictions, how you onboard — and produces a starting risk assessment and program document with your answers built in. It's free, and it's a genuine starting point rather than a blank template.

If you want it finished, reviewed and wired into your onboarding so the controls run themselves, that's our AML/CTF and client onboarding setup, from A$999 fixed price. No lock-in, and you deal with the person doing the work.

AUSTRAC's own guidance on AML/CTF programs is at austrac.gov.au.

Common questions

Can I use a template?

As a skeleton, yes. The risk assessment and the customer due diligence rules have to be specific to your business, so expect to rewrite those sections regardless of where the document came from.

Who has to approve it?

Your governing body — for a small firm, the owner, the partners or the board. Record the approval and the date.

How often do I update it?

Whenever something material changes, and at least on a regular cycle you set yourself. Annual is the common answer.

Do I have to send it to AUSTRAC?

Not routinely. You enrol, you operate under the program, and you produce it if AUSTRAC asks. That's why it needs to be findable and current.