What AML/CTF Program Documents Do You Need Before 1 July 2026?
By AML Guard | 20 April 2026 | 7 min read
From 1 July 2026, tranche 2 reporting entities must have a written AML/CTF program in place before providing a designated service. In practice, many firms document that program through four linked working documents. AML Guard generates all four through guided wizards — each one tailored to your entity type and built on the one before it.
Key Takeaways
- AUSTRAC requires a written, tailored AML/CTF program approved by a senior manager before 1 July 2026
- Many firms operationalise this through four linked working documents: risk assessment, policies, acceptance framework, and training materials
- AML Guard generates all four through guided wizards, each tailored to your entity type and sector
- First drafts typically take two to three hours of officer time for small-to-medium firms
- Documents include cross-references, version control, and drift detection when upstream inputs or guidance change
Most compliance tools help with identity checks. Far fewer help businesses build the written AML/CTF program AUSTRAC requires before a designated service is provided. For tranche 2 firms, that means more than buying screening software. It means documenting how your business identifies, manages and reviews risk, who makes key decisions, what procedures staff must follow, and how relevant personnel are trained.
AUSTRAC’s current guidance is clear on the core legal position: your AML/CTF program must be tailored to your business, documented in writing, approved by a senior manager, in place before you provide a designated service, and kept current over time. The program must include your risk assessment and your AML/CTF policies. Training is also mandatory for personnel who perform relevant AML/CTF functions, but businesses have flexibility in how they document and deliver that training.
For many agencies and practices, this is the hardest part of Tranche 2 readiness. Running an identity check is a transaction. Building a compliance program is a project. And most firms have never done it before.
The Blank Page Problem
The biggest barrier to Tranche 2 readiness is not technology. It is documentation.
A principal or compliance officer sitting down to write an AML/CTF program from scratch faces a daunting set of questions. What structure should the risk assessment follow? Which customer types need to be assessed, and how should risk positions be justified? What are the right acceptance thresholds? How should CDD procedures be documented? What should the training plan, training materials, and training records look like for a three-person agency versus a multi-office practice?
The most common responses are predictable: hire a consultant, or download a template.
Consultants can produce high-quality documentation, but the cost is often disproportionate for small-to-medium firms — and the documents still need to be maintained, updated, and version-controlled over time. If AUSTRAC guidance changes or the business model evolves, the consultant needs to come back.
Templates solve the cost problem but create a different one. A generic PDF does not know whether you are a residential sales agency, a buyer’s agent, a conveyancing practice, a law firm, or a developer. It cannot tailor your risk assessment to your business, and it cannot connect your training to your documented procedures. What you get is a starting point that still requires substantial manual work.
Neither approach produces documents that reference each other, update when upstream decisions change, or flag when AUSTRAC guidance evolves.
What AUSTRAC Requires — and How Firms Document It in Practice
AUSTRAC does not prescribe one universal template or a mandatory four-document bundle for every business. What it requires is a written AML/CTF program tailored to your business. That program must include your risk assessment and AML/CTF policies, and it must be approved by a senior manager before you provide a designated service.
In practice, many tranche 2 firms find it easier to operationalise those obligations through four linked working documents:
| Working Document | Legal Status | Practical Purpose |
|---|---|---|
| ML/TF Risk Assessment | Mandatory component of the AML/CTF program | Identifies and assesses the ML/TF risks your business reasonably faces, considering customer types, services, channels, and jurisdictions. |
| AML/CTF Policies and Procedures | Mandatory component of the AML/CTF program | Documents how your business manages risk, conducts CDD, reports suspicious matters, keeps records, and complies with its obligations. |
| Customer Acceptance and Escalation Framework | Usually documented within your AML/CTF policies rather than required as a standalone document | Helps staff apply consistent decisions about customer risk, onboarding conditions, and escalation paths. |
| Role-Based Training Plan, Materials and Register | Training is mandatory; a standalone manual is optional | Shows how relevant personnel are trained initially and on an ongoing basis, in a way appropriate to their role. |
Separating what the law strictly requires from the way well-run firms choose to document it is both more accurate and more defensible. A reviewer should be able to see that the business understood the obligations and made considered decisions about how to operationalise them.
Important: documents are necessary, but they are not the whole compliance program. A written program is foundational, but firms also need governance, role-appropriate training, record keeping, ongoing compliance with the documented procedures, and periodic independent evaluation. A good documentation workflow should make those next steps easier; it should not imply that generating documents alone completes your AML/CTF obligations.
How Guided Wizards Solve This
AML Guard generates all four working documents through a structured wizard suite where each document builds on the one before it.
Instead of starting from a blank page, the officer works through a guided sequence of decisions. At each step, the wizard presents the relevant question, explains the regulatory context, and offers expert-drafted starting positions that the officer can accept, modify, or replace. The output is a professional, review-ready Word document structured for internal approval, auditability, and easier review.
Entity Type Selection
The first decision is the entity’s operating model. The platform supports five primary entity types — real estate agency, buyer’s agency, conveyancing practice, solicitor or law firm, and developer — plus mixed-model businesses.
This selection is not cosmetic. It determines which services, customer types, risk factors, workflow examples, and governance structures appear throughout the entire wizard chain. A conveyancing practice sees different suggested positions and risk indicators than a residential sales agency. A solicitor sees legal professional privilege considerations that do not appear for agents. A developer sees off-the-plan transaction patterns irrelevant to a buyer’s agent.
Once confirmed, the entity type flows automatically into every downstream document.
Expert-Drafted Suggestions, Officer Decisions
At every governance decision point, the wizard offers pre-drafted suggested positions. These are expert-written, compliance-reviewed, sector-specific starting positions designed for small-to-medium Tranche 2 reporting entities.
The officer sees each suggestion as a selectable option. Click to accept and it populates the field. Edit to tailor it. Or write your own from scratch. The wizard does not force a position — it offers a defensible starting point that reduces the gap between an officer who knows their business and an officer who also needs to know how to express that in compliance language.
This matters because the quality of the final document depends on the quality of the inputs. A blank text field invites uncertainty. A suggested position that the officer reviews and confirms produces a document that is both substantive and genuinely the entity’s own.
The Dependency Chain
Each wizard reads from the one before it:
- Risk Assessment (10 steps): captures the entity’s business profile, designated services, customer types, geographic exposure, delivery channels, transaction characteristics, identified risks, control mapping, and residual risk positions. This is the foundation.
- Customer Acceptance and Escalation Framework (5 steps): reads customer type and risk data from the risk assessment. For each customer type, the officer sets an acceptance position — accept, accept with conditions, or decline — with mandatory rationale for high-risk types.
- AML/CTF Program (12 steps): reads from both upstream documents. Covers governance, compliance officer appointment, CDD procedures, reporting, record keeping, screening, tipping-off, and review schedule.
- Role-Based Training Plan, Materials and Register (7 steps): reads from the program and risk assessment. Generates role-specific training content for front-line staff, compliance officers, and senior management, drawn from the entity’s own documented procedures.
If the risk assessment is updated after downstream documents have been drafted, the system detects the change and flags it. The officer is prompted to review whether those documents need to be regenerated or re-confirmed. This drift detection extends to AUSTRAC guidance changes — if the platform’s content pack is updated, documents produced under the previous version are flagged for review.
Document Quality That Supports Review and Audit
The generated documents are structured for internal approval, auditability, and easier review.
Each document can include:
- Cover page with approval block — entity name, document title, version, date, and space for the senior manager’s sign-off.
- Table of contents — professional navigation for multi-section documents.
- Cross-reference table — sections mapped to the legal obligations they are intended to support, making review easier for the business, its advisers, and if required, AUSTRAC.
- Sector-appropriate language — the document reads as though it was written for your type of business, because it was. A conveyancer’s program does not contain real estate auction scenarios.
- Content provenance — the system distinguishes between platform-sourced data, suggested content the officer reviewed, and officer-authored governance text.
- Version control and drift detection — every document records its content version and the state of its upstream dependencies at the time of generation.
The output is a Word document — not a locked PDF. Officers can print it, annotate it, share it with their senior manager for review, and file the approved version as their compliance record.
Getting Started
The wizard suite is available to all AML Guard subscribers. The typical path:
- Risk Assessment: 30–45 minutes for the first pass through 10 guided steps.
- Customer Acceptance and Escalation Framework: 15–20 minutes. Most context is pre-populated from the risk assessment.
- AML/CTF Program: 45–60 minutes for a thorough first pass through all 12 steps.
- Role-Based Training Plan, Materials and Register: 20–30 minutes. Content is largely generated from the program and risk profile.
For many small-to-medium firms, a first draft of the four-document package can often be produced in roughly two to three hours of officer time, depending on business complexity and how quickly internal decisions are made. Not two to three weeks. Not two to three thousand dollars. And the documents are yours — tailored, connected, and ready for senior manager review and approval.
Once the program package is approved, the next step is staff training. Read the companion guide: AML/CTF Staff Training Under Tranche 2 — What Your Team Needs to Know, In Six Languages.
Frequently Asked Questions
These are the questions most firms ask once they move from identity checks to full program build-out.
What documents do you need for an AML/CTF program?
AUSTRAC requires a written AML/CTF program that includes your ML/TF risk assessment and your AML/CTF policies. Many firms find it practical to document these as separate, linked working documents — typically a risk assessment, policies and procedures, a customer acceptance and escalation framework, and role-based training materials. The specific structure is up to the business, provided the program is tailored, written, approved by a senior manager, and in place before designated services are provided. Businesses also need to plan for periodic independent evaluation of the program and keep it current as their risks, services, or procedures change.
Does AUSTRAC prescribe a specific document format?
No. AUSTRAC requires the program to be in writing, tailored to the business, and approved by a senior manager. The format, structure, and number of separate documents is a business decision. What matters is that the content is substantive, the risk assessment is genuinely tailored, and the program is operationalised — not just filed.
Who must approve an AML/CTF program?
A senior manager must approve your AML/CTF program, including the risk assessment and policies, before you begin providing designated services. AUSTRAC’s guidance defines who can fill this role and notes that senior managers are accountable for the adequacy and implementation of the program.
When must tranche 2 entities have their program in place?
Before providing a designated service from 1 July 2026. The program must be in place, approved, and operational — not just in draft. Firms should allow adequate time before the deadline for drafting, senior manager review, staff training, and any refinement needed.
Can I use AUSTRAC’s starter kit instead of writing my own program?
AUSTRAC has published a program starter kit for small real estate and buyer’s agencies that meet specific suitability criteria. The criteria cover designated service scope, personnel count, customer mix, geographic focus, and business structure. Larger, more complex, or less standardised businesses should assess the published suitability criteria carefully before assuming the starter kit will be sufficient.
What happens if I don’t have an AML/CTF program by 1 July 2026?
Operating without an AML/CTF program means providing designated services without the required compliance framework. AUSTRAC has broad enforcement powers, including civil penalties, infringement notices, enforceable undertakings, and remedial directions. Beyond formal penalties, the absence of a documented program means no structured basis for compliance decisions and no evidence to produce if AUSTRAC requests it.
How often does an AML/CTF program need to be reviewed?
Your program must be kept current and reviewed when there are material changes to your business, risk profile, services, or when AUSTRAC guidance changes. An independent evaluation of the program is also required periodically. Businesses should build a review schedule into their compliance calendar rather than treating the program as a one-time document.
Sources
AUSTRAC guidance: Your AML/CTF program overview
AUSTRAC guidance: Senior manager
AUSTRAC guidance: Newly regulated businesses – get ready for reforms
AML/CTF Act 2006
AML/CTF Rules Instrument 2025
Last reviewed: April 2026.
Ready to see AML Guard in action?
AML Guard covers the full AML/CTF program lifecycle — from CDD case management and identity verification to beneficial ownership tracing, risk scoring, program governance, AUSTRAC reporting, and CRM integration. Book a 20-minute demo.
Related Reading
When Does AML Compliance Actually Start in a Property Transaction?
What Is an AML/CTF Program? A Plain-English Guide for Property Professionals
AML/CTF Compliance Checklist for Real Estate Agents
Beneficial Ownership: How to Trace UBOs Under Tranche 2
This article is for general information purposes only and does not constitute legal or compliance advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.