AML/CTF policy template for Tranche 2 firms

AML/CTF policy template for Tranche 2 firms

What a compliant AML/CTF policy contains, how to tailor a template to your own risk assessment, and what an independent reviewer will look for.

AML/CTF Compliance 31 August 2026 8 min read AML Guard

A properly built AML policy template can meet AUSTRAC requirements, but only once it is customised to your firm’s business-wide ML/TF risk assessment, names an accountable compliance officer, and carries governing-body sign-off. Start by mapping the template against your risk assessment, confirming who holds the AML/CTF compliance officer role and who covers it in their absence, and booking an independent review before you rely on it. AUSTRAC and the AML/CTF Act 2006 (Cth) set the bar; a downloaded document alone does not clear it.


TL;DR:


Table of Contents

What’s the difference between a program, a policy and a procedure?

Businesses get this wrong constantly, and it costs them at audit time. The AML/CTF program is the whole obligation: the umbrella that covers everything your firm does to manage money laundering and terrorism financing risk. Since the 2024 amendments, that program has two limbs, not the Part A and Part B split some guides still describe. Limb one is the business-wide ML/TF risk assessment, built under section 26C of the Act. Limb two is your AML/CTF policies, the subject of this article.

Your policy is what the firm commits to doing. It states, in plain terms, how you will identify customers, when you will escalate a matter, who signs off on decisions, and how long records are kept. Your procedures are how staff actually do it day to day: the onboarding checklist, the verification workflow inside your case management system, the exact screen a receptionist uses to capture a passport scan.

AML policy commitments linked to procedures

Conflating these three creates two failure modes. Some firms write a program document so detailed it duplicates operational procedure, which becomes obsolete the moment a system changes. Others write a policy so generic it could belong to any business in the country, and that is the version supervisors flag hardest. This article covers the policy layer only. If you need help with the risk assessment itself, AUSTRAC’s own AML/CTF reform guidance is the authoritative starting point.

What a compliant AML policy must include

A compliant AML/CTF policy is not a mission statement. It is a working document that a supervisor or an independent reviewer can trace back to your actual risk profile and your actual operations. Several elements are non-negotiable regardless of firm size.

A firm can tick every one of these boxes on paper and still fail review if the content doesn’t match reality. As practical guidance from AMLCC on writing a compliant AML policy makes clear, an uncustomised template is not a defence in a review. It is a documented gap, because it proves the firm adopted generic language instead of assessing its own risk.

How do you customise a template for your firm?

Converting a generic document into something AUSTRAC would recognise as fit for purpose is mechanical work, not creative writing. Follow these steps in order.

  1. Map every clause to your risk assessment. For each section of the template, ask which specific risk it addresses and whether that risk actually appears in your firm’s assessment. Delete or rewrite anything that doesn’t connect.
  2. Replace generic phrasing with named systems and roles. “Customer identity will be verified” becomes “identity is verified using [specific verification method], captured in [specific system], reviewed by [named role].”
  3. Spell out EDD triggers with exact measures. Instead of “enhanced due diligence will be applied where appropriate,” state the trigger (a politically exposed person, a trust with no clear settlor, a transaction from a high-risk jurisdiction) and the exact response: source-of-funds checks, senior manager approval, and a defined review frequency.
  4. Keep procedures out of the policy text. The policy states the commitment; separate operational documents, such as an onboarding checklist or a verification workflow, carry the step-by-step detail. According to guidance from FigsFlow’s AML policy writing guide, a short, tailored policy paired with clear procedures reads far better to a supervisor than one long document that mixes both.
  5. Set version control and a review cadence. Every update needs a date, a version number, and a record of governing-body sign-off.

Pro Tip: Keep an exceptions register alongside your policy. Every time a staff member departs from a stated procedure, log why, and tie that entry back to the relevant risk in your assessment. It becomes the single most useful document an independent reviewer will ask for.

Practical checklist: final steps before approving the policy

Before your governing body signs off, run through this list. Missing any one of these items is the difference between a document that looks compliant and one that actually is.

Firms in real estate, conveyancing and settlement work will recognise most of these steps from onboarding files already. AML Guard’s own AML/CTF compliance checklist for real estate agents walks through the same requirements in more operational detail if your firm is still building out staff-level procedures.

Governance and independent review: what to expect

Governing-body approval isn’t a formality. It is the record that shows the firm’s leadership actually understood and accepted the risk profile the policy is built on, not just that someone signed a cover page. That approval should record the date, the version reviewed, and who sat on the decision.

An independent reviewer, whether internal or external, works through a fairly consistent set of checks:

Supervisors, according to the AMLCC guidance on compliant policies, look for evidence the policy is applied, not just well written. A new service line, a regulatory update, or a material shift in client risk (a sudden run of overseas buyers, for instance) should trigger a policy update well before the scheduled review date.

Why AML Guard builds linked, not standalone, documents

Why AML Guard builds linked, not standalone, documents — overview diagram

Standalone templates create a structural problem: the policy, the risk assessment and the training manual are written at different times, by different people, and they drift apart. AML Guard takes a different approach. Its guided wizards generate the AML/CTF program documents as one linked set, built from the same underlying answers, so the policy reflects the risk assessment and the training manual reflects the policy.

That matters because a supervisor checks consistency first. End-to-end CDD, beneficial ownership determination on a company’s ACN with trusts reached through their corporate trustee, suspicious matter workflows and a tamper-evident audit trail all sit inside the same platform, generating the evidence a reviewer will ask for. If you want to see how linked documents behave in practice rather than in theory, booking a demo is the most direct way to find out.

How AML Guard can help you get audit-ready

A template only earns its place once it’s tailored to your risk assessment, backed by a named compliance officer, and signed off by your governing body. AML Guard is built for exactly that step, turning the policy layer into a living document tied to real evidence rather than a file that sits untouched until an audit forces someone to open it.

AML Guard dashboard showing linked AML/CTF program documents

The platform’s guided policy wizards generate AML/CTF policies alongside your risk assessment and training manual, so the three stay consistent by design. Beyond drafting, it runs identity verification and ongoing CDD, traces beneficial ownership through companies, trusts and SMSFs, manages suspicious matter and threshold transaction reporting workflows, and keeps a seven-year audit trail ready for review. Firms already running REX CRM get compliance status pushed through automatically, without exposing sensitive CDD data outside the platform.

If your policy still reads like it was written for a different business, book a demo with AML Guard and see how a linked set of program documents holds up against an independent review before AUSTRAC or your own compliance officer finds the gap first.

Sources

See How AML Guard Works

Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo
This article is for general information purposes only and does not constitute legal advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.
Last reviewed: 31 August 2026.