AML training manual for Tranche 2 firms

AML training manual for Tranche 2 firms

What a defensible AML/CTF training manual contains, who needs vetting before they are trained, and what records AUSTRAC expects you to keep.

AML/CTF Compliance 5 September 2026 13 min read AML Guard

Your AML/CTF training manual must be a risk-mapped, auditable artefact linked to your business-wide ML/TF risk assessment and AML/CTF policies. It needs to name who gets trained, what they learn, and when. It needs a retained, tamper-evident record of who completed it and how well. Anchor everything to AUSTRAC, the AML/CTF Act 2006 (Cth), and the AML/CTF Rules 2025, or the manual is just a document nobody can defend.


TL;DR:


Table of Contents

What does the AUSTRAC training obligation actually cover?

The obligation reaches further than most compliance officers assume. It applies to any employee, contractor, or agent who performs a function that touches your designated services. That includes frontline staff handling customer due diligence, settlement agents processing property transactions, and senior management who sign off on risk decisions. It also includes third-party contractors doing work on your behalf, not just payroll staff.

Training cannot sit as a standalone policy separate from everything else. It has to live inside your AML/CTF policies and connect visibly back to your risk assessment. AUSTRAC’s reform guidance is blunt about this, under Act section 26F(4)(e) and Rules section 5–9(2): training content must be tailored to the risks your firm has actually identified, and not lifted from a generic template that mentions services you don’t provide.

For firms newly caught by Tranche 2 obligations, this scoping question matters even more. AUSTRAC’s Tranche 2 guidance sets out which real estate, legal, accounting, and trust and company service roles are captured, and the training obligation follows the same boundary lines.

When you’re scoping who needs what level of training, work through these categories:

AUSTRAC expects training that is role-specific, evidenceable, and demonstrably tied to your firm’s own risk profile, not a one-size-fits-all module bought off a shelf and left untouched for years.

What should a compliant training manual actually contain?

A defensible manual is built around content areas that map directly to your obligations under the Act and the AML/CTF Rules 2025, not a vague overview of “money laundering awareness.” Every module needs a stated learning objective and a way to prove the objective was met.

  1. Customer due diligence and enhanced CDD — identity verification standards, when enhanced due diligence triggers, and how staff document decisions.
  2. Beneficial ownership identification — how to trace ownership through companies, trusts, and SMSFs, including corporate trustee structures.
  3. Suspicious matter report procedures — internal escalation paths, timeframes, and what counts as reasonable grounds under section 41.
  4. Threshold transaction reporting — recognising reportable transactions and the internal handoff to your reporting function.
  5. Sanctions and PEP screening — how screening alerts are actioned and who has authority to clear or escalate a match.
  6. Record-keeping obligations — what must be retained, for how long, and in what format.

Each module needs role-specific outcomes. A settlement agent doesn’t need the same depth on sanctions screening as your compliance officer, but they do need to recognise a red flag and know exactly who to tell. Measurable assessment is what turns a training session into evidence: a scored scenario exercise, a short written case response, or a signed attestation confirming the staff member understood the material and their reporting duties.

Pro Tip: Build one scenario exercise per module using a de-identified example from your own client base rather than a textbook case study. AUSTRAC’s own guidance on assessing suspicious activity notes that generic training disconnected from real transactions is one of the most common audit failures.

How do you tailor training to your risk assessment?

Training built without reference to your business-wide ML/TF risk assessment is the single most common reason a manual fails scrutiny. AUSTRAC has flagged inconsistency between artefacts as a primary audit trigger — a training manual that lists designated services your risk assessment doesn’t mention is an immediate red flag to an inspector.

The fix is mechanical, not mysterious. Take each high-risk typology your risk assessment identifies and turn it into a scenario your staff will actually encounter.

Version control matters here as much as content. When your risk assessment is updated, your training manual needs a corresponding update, and you need a log showing the link between the two changes. AUSTRAC’s Tranche 2 materials recommend maintaining an approval and version log for every manual change, tied explicitly to the risk assessment revision that triggered it. A manual with no version history looks static, and static training is exactly what AUSTRAC treats as a warning sign.

When should training happen, and what records do you need to keep?

Training has natural trigger points beyond a fixed annual date: onboarding, a role change, a new designated service, or a shift in typology risk flagged by AUSTRAC. There is no single statutory interval for refresher training, but AUSTRAC’s good practice guidance points to a sensible rhythm.

AUSTRAC’s position is clear on one point that catches firms out repeatedly: training completion records must be auditable, not just delivered. A module someone clicked through without a retained score, date, and sign-off is functionally undocumented training.

Every record needs to answer five questions an inspector will ask: who was trained, on which module, what score or outcome they achieved, on what date, and who signed off on completion. Store these records in a format that can’t be quietly edited after the fact — tamper-evident storage, not just a spreadsheet anyone with access can retype.

Which delivery methods actually produce evidence AUSTRAC will accept?

There’s no single mandated delivery format, and AUSTRAC does not accredit training providers or courses. What matters is whether your chosen method produces the specific evidence an inspector expects to see.

Delivery method Retention strength Minimum evidence produced
E-learning modules Consistent, scalable Completion timestamp, quiz score, module version
Instructor-led sessions Strong for complex scenarios Attendance log, facilitator notes, assessment outcome
On-the-job coaching High for practical skills Manager attestation, coaching log, competency sign-off
Blended (e-learning plus workshop) Strongest overall All of the above, cross-referenced by date

E-learning scales well across multiple offices and is easy to standardise, but it can slide into passive click-through unless the assessment component is genuinely scored. Instructor-led sessions handle nuanced scenario work better, particularly for high-risk role training, but they generate less consistent paperwork unless attendance and outcomes are logged every time. On-the-job coaching builds real competency fastest but is the hardest to evidence unless a manager signs off formally.

Whichever mix you choose, multilingual delivery needs the same record linkage as English-language modules. A completion record in Vietnamese or Mandarin still needs a date, a score, and a sign-off tied back to the same audit trail as everyone else’s.

Should you outsource training content, or build it yourself?

Because AUSTRAC does not accredit or approve training providers, buying an off-the-shelf course doesn’t transfer responsibility for its adequacy. You still own the outcome, which means procurement needs a checklist, not a leap of faith.

Standard content is usually fine for general awareness modules covering universal concepts like record-keeping basics. Bespoke modules become necessary the moment you’re training staff on scenarios specific to your risk assessment, your client base, or a designated service most off-the-shelf libraries don’t cover well.

Who needs vetting before they need training?

Training someone you haven’t vetted doesn’t discharge your obligation. Personnel due diligence and training are a pair, and AUSTRAC treats them as linked expectations, not separate boxes to tick in either order.

Before anyone in an AML/CTF role starts training, you need documented checks covering their skills, knowledge, expertise, and integrity. That means:

The AML/CTF compliance officer needs an additional layer above this baseline: a fit and proper assessment covering relevant experience, demonstrated integrity, independence from conflicting business interests, and freedom from conflicts that could compromise their judgement on escalation decisions.

Pro Tip: Store your vetting records and training completion records in the same reference system, cross-linked by employee ID. When an inspector asks whether a staff member was both vetted and trained for their role, you want one query to answer both questions, not two separate filing cabinets.

Vetting and training records linked together

How do you structure a manual you can actually defend?

A workable manual skeleton follows a logical sequence an inspector can trace from obligation to evidence.

  1. Purpose and scope — which staff, contractors, and functions the manual covers, cross-referenced to your risk assessment.
  2. Governance — who owns the manual, who approves updates, and the version log format.
  3. Core modules — CDD/ECDD, beneficial ownership, SMR procedures, threshold reporting, sanctions screening, record-keeping.
  4. Role-specific modules — tailored content for high-risk functions identified in your risk assessment.
  5. Assessment methods — scenario exercises, quizzes, attestations, and the passing standard for each.
  6. Delivery and scheduling — onboarding triggers, refresher cadence, and delivery method per role.
  7. Record-keeping and retention — what’s stored, for how long, and in what tamper-evident format.
  8. Review and update log — dated entries showing every change and its link to a risk assessment revision.

A worked example makes the skeleton concrete. Take a property settlement scenario module: the objective is recognising unusual deposit or funding-source patterns during conveyancing. The core content covers CDD standards for verifying the funding source. The scenario presents a buyer offering a cash deposit inconsistent with their declared income profile. The assessment is a short written response describing the correct escalation path. The required record is a scored response, a date, and a supervisor sign-off, stored against that employee’s training file.

Every section needs a named owner and a sign-off checklist before it goes live, and every subsequent edit needs the same discipline applied to the version log.

How do you know if your training is actually working?

Delivering training isn’t the same as proving it works. Track completion rates and pass rates by role, but also watch for the metrics that reveal whether the content is genuinely landing: how often a trained staff member still misses a red flag, how long it takes to remediate a gap once identified, and whether audit findings keep repeating on the same topic year after year.

Build training review into your existing compliance calendar rather than treating it as a separate annual event. When your risk assessment gets updated, that update should trigger an automatic review of training content, not a note to “look at this eventually.” Immediate retraining triggers include a new typology flagged by AUSTRAC, an internal incident revealing a knowledge gap, or a regulatory change to the Rules. Document the corrective action plan every time, with dates and named owners, because an inspector will ask what you did after you found the gap, not just whether you found it.

The recurring theme in AUSTRAC’s own commentary is consistency: a training manual that names different designated services or risk typologies to your risk assessment is the fastest way to fail an audit. AML Guard was built around that exact problem. Its guided wizards produce the business-wide ML/TF risk assessment, the AML/CTF policies, the compliance action plan, and the staff training manual as one linked set, generated from the same underlying answers.

Because all four artefacts come from the same source data, a module addressing trust and company risk in a training manual matches the wording in policies and the exposure identified in the risk assessment. That alignment is what a supervisor checks first.

None of this implies AUSTRAC endorsement of any platform. What it does is give you an organised evidence pack ready to present the day an inspector asks for one.

What compliance officers get wrong about “finishing” a training manual

The manuals that fail audits are rarely bad on the day they’re written. They fail because nobody circled back when the risk assessment changed six months later. A living manual needs an owner with a standing calendar reminder, not a project that gets closed once and forgotten.

Micro-learning beats annual marathon sessions for retention, and a five-minute scenario refresh tied to a real near-miss sticks better than a slide deck nobody remembers by March. The internal budget argument writes itself once you frame training against the cost of a failed audit finding rather than against a training line item in isolation.

How AML Guard supports a defensible training manual

Building a training manual from scratch, then keeping it aligned to your risk assessment every time something changes, is exactly the workload that turns compliance officers into overnight document controllers. AML Guard’s advantage over a downloaded template or a static course library is structural: your training manual, your policies, and your risk assessment are generated from the same guided wizard, so they can’t quietly drift apart the way separately sourced documents do.

AML Guard training completion records linked to the risk assessment

The platform tracks completion by role, stores results in a tamper-evident audit trail, and links training status to the same governance dashboard covering your CDD and reporting obligations. If you’re a real estate agency, law firm, conveyancing practice, or trust and company service provider building this out for the first time, the AML Guard platform is worth a look before you commit to a static template. Book a demo to see how your risk assessment, policies, and training manual come together as one evidenced set, ready the day an inspector asks for it.

Sources

See How AML Guard Works

Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo
This article is for general information purposes only and does not constitute legal advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.
Last reviewed: 5 September 2026.