A properly built AML policy template can meet AUSTRAC requirements, but only once it is customised to your firm’s business-wide ML/TF risk assessment, names an accountable compliance officer, and carries governing-body sign-off. Start by mapping the template against your risk assessment, confirming who holds the AML/CTF compliance officer role and who covers it in their absence, and booking an independent review before you rely on it. AUSTRAC and the AML/CTF Act 2006 (Cth) set the bar; a downloaded document alone does not clear it.
TL;DR:
- A compliant AML policy must be tailored to your firm’s risk assessment, with clear linkage, named roles, and documented review processes.
- Customisation involves mapping each clause to specific risks, replacing generic language, and defining exact EDD triggers and responses.
- An independent review and formal governing-body approval are critical, ensuring the policy reflects actual operations and risk profile.
- AML Guard generates policies, the risk assessment and the training manual as one linked set, so they stay consistent with each other and an audit trail sits behind every change.
- Merely downloading a template is insufficient; it requires thorough adaptation and backing by evidence to pass AUSTRAC review.
Table of Contents
- What’s the difference between a program, a policy and a procedure?
- What a compliant AML policy must include
- How do you customise a template for your firm?
- Practical checklist: final steps before approving the policy
- Governance and independent review: what to expect
- Why AML Guard builds linked, not standalone, documents
- How AML Guard can help you get audit-ready
- Sources
What’s the difference between a program, a policy and a procedure?
Businesses get this wrong constantly, and it costs them at audit time. The AML/CTF program is the whole obligation: the umbrella that covers everything your firm does to manage money laundering and terrorism financing risk. Since the 2024 amendments, that program has two limbs, not the Part A and Part B split some guides still describe. Limb one is the business-wide ML/TF risk assessment, built under section 26C of the Act. Limb two is your AML/CTF policies, the subject of this article.
Your policy is what the firm commits to doing. It states, in plain terms, how you will identify customers, when you will escalate a matter, who signs off on decisions, and how long records are kept. Your procedures are how staff actually do it day to day: the onboarding checklist, the verification workflow inside your case management system, the exact screen a receptionist uses to capture a passport scan.

Conflating these three creates two failure modes. Some firms write a program document so detailed it duplicates operational procedure, which becomes obsolete the moment a system changes. Others write a policy so generic it could belong to any business in the country, and that is the version supervisors flag hardest. This article covers the policy layer only. If you need help with the risk assessment itself, AUSTRAC’s own AML/CTF reform guidance is the authoritative starting point.
What a compliant AML policy must include
A compliant AML/CTF policy is not a mission statement. It is a working document that a supervisor or an independent reviewer can trace back to your actual risk profile and your actual operations. Several elements are non-negotiable regardless of firm size.
- Scope and application — which designated services the policy covers and the point at which obligations begin (onboarding, before settlement, before file opening).
- Link to the risk assessment — every control in the policy should trace back to a specific risk identified in your business-wide ML/TF risk assessment, not a generic industry risk.
- Customer due diligence (CDD) and ongoing due diligence — identity verification standards, the triggers for re-verification, and how beneficial ownership is established for companies, trusts and self-managed super funds.
- Enhanced due diligence (EDD) triggers — the specific circumstances (politically exposed persons, high-risk jurisdictions, complex ownership) that lift a matter into extra scrutiny, and what that scrutiny involves.
- Suspicious matter reporting (SMR) and threshold transaction reporting (TTR) — internal escalation steps, who decides, and reporting timeframes.
- Governance — a named AML/CTF compliance officer, who covers the role in their absence, and the governing body’s oversight role.
- Record keeping — retention for seven years, version control on the policy itself, and an audit trail of who approved what and when.
- Training and employee due diligence — screening new staff, scheduled refresher training, and evidence that training actually happened.
A firm can tick every one of these boxes on paper and still fail review if the content doesn’t match reality. As practical guidance from AMLCC on writing a compliant AML policy makes clear, an uncustomised template is not a defence in a review. It is a documented gap, because it proves the firm adopted generic language instead of assessing its own risk.
How do you customise a template for your firm?
Converting a generic document into something AUSTRAC would recognise as fit for purpose is mechanical work, not creative writing. Follow these steps in order.
- Map every clause to your risk assessment. For each section of the template, ask which specific risk it addresses and whether that risk actually appears in your firm’s assessment. Delete or rewrite anything that doesn’t connect.
- Replace generic phrasing with named systems and roles. “Customer identity will be verified” becomes “identity is verified using [specific verification method], captured in [specific system], reviewed by [named role].”
- Spell out EDD triggers with exact measures. Instead of “enhanced due diligence will be applied where appropriate,” state the trigger (a politically exposed person, a trust with no clear settlor, a transaction from a high-risk jurisdiction) and the exact response: source-of-funds checks, senior manager approval, and a defined review frequency.
- Keep procedures out of the policy text. The policy states the commitment; separate operational documents, such as an onboarding checklist or a verification workflow, carry the step-by-step detail. According to guidance from FigsFlow’s AML policy writing guide, a short, tailored policy paired with clear procedures reads far better to a supervisor than one long document that mixes both.
- Set version control and a review cadence. Every update needs a date, a version number, and a record of governing-body sign-off.
Pro Tip: Keep an exceptions register alongside your policy. Every time a staff member departs from a stated procedure, log why, and tie that entry back to the relevant risk in your assessment. It becomes the single most useful document an independent reviewer will ask for.
Practical checklist: final steps before approving the policy
Before your governing body signs off, run through this list. Missing any one of these items is the difference between a document that looks compliant and one that actually is.
- Every policy statement traces back to a specific line in the firm-wide risk assessment.
- The AML/CTF compliance officer is named, with a deputy identified and contact details recorded.
- CDD and EDD procedures link to the actual forms and systems staff use, and someone has tested that link works in practice.
- The SMR and TTR workflow is documented end to end, including internal escalation and who signs off on a report.
- Record-retention start dates, storage location, and access controls are confirmed for the full seven-year period.
- Staff training is scheduled, completion is recorded, and evidence of that record is retained.
- An independent review or external compliance check has been arranged, and its outcomes will be documented, not just discussed.
Firms in real estate, conveyancing and settlement work will recognise most of these steps from onboarding files already. AML Guard’s own AML/CTF compliance checklist for real estate agents walks through the same requirements in more operational detail if your firm is still building out staff-level procedures.
Governance and independent review: what to expect
Governing-body approval isn’t a formality. It is the record that shows the firm’s leadership actually understood and accepted the risk profile the policy is built on, not just that someone signed a cover page. That approval should record the date, the version reviewed, and who sat on the decision.
An independent reviewer, whether internal or external, works through a fairly consistent set of checks:
- Does the policy align with the current risk assessment, or has the business changed since the last review?
- Is CDD complete for the customer types the firm actually deals with, including beneficial ownership for trusts and companies?
- Are SMR and TTR procedures adequate, and is the record keeping behind them intact?
- Where corrective actions were raised previously, is there evidence they were implemented, not just noted?
Supervisors, according to the AMLCC guidance on compliant policies, look for evidence the policy is applied, not just well written. A new service line, a regulatory update, or a material shift in client risk (a sudden run of overseas buyers, for instance) should trigger a policy update well before the scheduled review date.
Why AML Guard builds linked, not standalone, documents

Standalone templates create a structural problem: the policy, the risk assessment and the training manual are written at different times, by different people, and they drift apart. AML Guard takes a different approach. Its guided wizards generate the AML/CTF program documents as one linked set, built from the same underlying answers, so the policy reflects the risk assessment and the training manual reflects the policy.
That matters because a supervisor checks consistency first. End-to-end CDD, beneficial ownership determination on a company’s ACN with trusts reached through their corporate trustee, suspicious matter workflows and a tamper-evident audit trail all sit inside the same platform, generating the evidence a reviewer will ask for. If you want to see how linked documents behave in practice rather than in theory, booking a demo is the most direct way to find out.
How AML Guard can help you get audit-ready
A template only earns its place once it’s tailored to your risk assessment, backed by a named compliance officer, and signed off by your governing body. AML Guard is built for exactly that step, turning the policy layer into a living document tied to real evidence rather than a file that sits untouched until an audit forces someone to open it.

The platform’s guided policy wizards generate AML/CTF policies alongside your risk assessment and training manual, so the three stay consistent by design. Beyond drafting, it runs identity verification and ongoing CDD, traces beneficial ownership through companies, trusts and SMSFs, manages suspicious matter and threshold transaction reporting workflows, and keeps a seven-year audit trail ready for review. Firms already running REX CRM get compliance status pushed through automatically, without exposing sensitive CDD data outside the platform.
If your policy still reads like it was written for a different business, book a demo with AML Guard and see how a linked set of program documents holds up against an independent review before AUSTRAC or your own compliance officer finds the gap first.
Sources
Recommended
- AML/CTF Compliance Checklist for Real Estate Agents: What You Need Before 1 July 2026
- AML/CTF Program Documents for Tranche 2
- What Is an AML/CTF Program? A Plain-English Guide for Property Professionals
- Tranche 2 AML/CTF Guide for Australian Real Estate Agents | 1 July 2026
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.