Your AML/CTF training manual must be a risk-mapped, auditable artefact linked to your business-wide ML/TF risk assessment and AML/CTF policies. It needs to name who gets trained, what they learn, and when. It needs a retained, tamper-evident record of who completed it and how well. Anchor everything to AUSTRAC, the AML/CTF Act 2006 (Cth), and the AML/CTF Rules 2025, or the manual is just a document nobody can defend.
TL;DR:
- Training must be role-specific, evidenceable, and directly linked to your business’s risk assessment to meet AUSTRAC compliance requirements.
- Content should cover key areas such as customer due diligence, beneficial ownership, suspicious activity reporting, and sanctions screening, with tailored scenarios for high-risk functions.
- Training records must include who was trained, on what module, their outcome, and date, stored in tamper-evident systems to withstand audit scrutiny.
- Updating the training manual should follow risk assessment revisions, with version control logs that connect each change to specific risk typologies.
- Using integrated platforms like AML Guard ensures alignment of policies, risk assessments, and training records, facilitating evidence-based audits.
Table of Contents
- What does the AUSTRAC training obligation actually cover?
- What should a compliant training manual actually contain?
- How do you tailor training to your risk assessment?
- When should training happen, and what records do you need to keep?
- Which delivery methods actually produce evidence AUSTRAC will accept?
- Should you outsource training content, or build it yourself?
- Who needs vetting before they need training?
- How do you structure a manual you can actually defend?
- How do you know if your training is actually working?
- How AML Guard links training to the rest of your compliance program
- What compliance officers get wrong about “finishing” a training manual
- How AML Guard supports a defensible training manual
- Sources
What does the AUSTRAC training obligation actually cover?
The obligation reaches further than most compliance officers assume. It applies to any employee, contractor, or agent who performs a function that touches your designated services. That includes frontline staff handling customer due diligence, settlement agents processing property transactions, and senior management who sign off on risk decisions. It also includes third-party contractors doing work on your behalf, not just payroll staff.
Training cannot sit as a standalone policy separate from everything else. It has to live inside your AML/CTF policies and connect visibly back to your risk assessment. AUSTRAC’s reform guidance is blunt about this, under Act section 26F(4)(e) and Rules section 5–9(2): training content must be tailored to the risks your firm has actually identified, and not lifted from a generic template that mentions services you don’t provide.
For firms newly caught by Tranche 2 obligations, this scoping question matters even more. AUSTRAC’s Tranche 2 guidance sets out which real estate, legal, accounting, and trust and company service roles are captured, and the training obligation follows the same boundary lines.
When you’re scoping who needs what level of training, work through these categories:
- Frontline CDD staff: anyone opening files, verifying identity, or collecting beneficial ownership information.
- Transaction and settlement roles: conveyancers, agents, and support staff handling funds movement or settlement documentation.
- Senior management and directors: people approving risk decisions or signing off on the AML/CTF program.
- The AML/CTF compliance officer: deeper, role-specific training beyond general awareness content.
- Contractors and outsourced service providers: anyone performing a designated service function under your instruction.
AUSTRAC expects training that is role-specific, evidenceable, and demonstrably tied to your firm’s own risk profile, not a one-size-fits-all module bought off a shelf and left untouched for years.
What should a compliant training manual actually contain?
A defensible manual is built around content areas that map directly to your obligations under the Act and the AML/CTF Rules 2025, not a vague overview of “money laundering awareness.” Every module needs a stated learning objective and a way to prove the objective was met.
- Customer due diligence and enhanced CDD — identity verification standards, when enhanced due diligence triggers, and how staff document decisions.
- Beneficial ownership identification — how to trace ownership through companies, trusts, and SMSFs, including corporate trustee structures.
- Suspicious matter report procedures — internal escalation paths, timeframes, and what counts as reasonable grounds under section 41.
- Threshold transaction reporting — recognising reportable transactions and the internal handoff to your reporting function.
- Sanctions and PEP screening — how screening alerts are actioned and who has authority to clear or escalate a match.
- Record-keeping obligations — what must be retained, for how long, and in what format.
Each module needs role-specific outcomes. A settlement agent doesn’t need the same depth on sanctions screening as your compliance officer, but they do need to recognise a red flag and know exactly who to tell. Measurable assessment is what turns a training session into evidence: a scored scenario exercise, a short written case response, or a signed attestation confirming the staff member understood the material and their reporting duties.
Pro Tip: Build one scenario exercise per module using a de-identified example from your own client base rather than a textbook case study. AUSTRAC’s own guidance on assessing suspicious activity notes that generic training disconnected from real transactions is one of the most common audit failures.
How do you tailor training to your risk assessment?
Training built without reference to your business-wide ML/TF risk assessment is the single most common reason a manual fails scrutiny. AUSTRAC has flagged inconsistency between artefacts as a primary audit trigger — a training manual that lists designated services your risk assessment doesn’t mention is an immediate red flag to an inspector.
The fix is mechanical, not mysterious. Take each high-risk typology your risk assessment identifies and turn it into a scenario your staff will actually encounter.
- If your risk assessment flags cash-heavy property purchases as elevated risk, build a scenario module around a buyer offering an unusual deposit structure.
- If trust and company work is a flagged exposure, include a module on tracing beneficial ownership through a corporate trustee.
- If foreign PEP exposure is identified in conveyancing work, build a screening escalation scenario specific to that risk.
Version control matters here as much as content. When your risk assessment is updated, your training manual needs a corresponding update, and you need a log showing the link between the two changes. AUSTRAC’s Tranche 2 materials recommend maintaining an approval and version log for every manual change, tied explicitly to the risk assessment revision that triggered it. A manual with no version history looks static, and static training is exactly what AUSTRAC treats as a warning sign.
When should training happen, and what records do you need to keep?
Training has natural trigger points beyond a fixed annual date: onboarding, a role change, a new designated service, or a shift in typology risk flagged by AUSTRAC. There is no single statutory interval for refresher training, but AUSTRAC’s good practice guidance points to a sensible rhythm.
- New starters and contractors: general awareness training before they touch a designated service function.
- Compliance officers and senior management: refresher training roughly every 6 to 12 months, reflecting their deeper exposure to decision-making risk.
- General staff: onboarding training plus periodic refreshers when risk findings or procedures change.
- Role changes: targeted retraining whenever someone moves into a higher-risk function.
AUSTRAC’s position is clear on one point that catches firms out repeatedly: training completion records must be auditable, not just delivered. A module someone clicked through without a retained score, date, and sign-off is functionally undocumented training.
Every record needs to answer five questions an inspector will ask: who was trained, on which module, what score or outcome they achieved, on what date, and who signed off on completion. Store these records in a format that can’t be quietly edited after the fact — tamper-evident storage, not just a spreadsheet anyone with access can retype.
Which delivery methods actually produce evidence AUSTRAC will accept?
There’s no single mandated delivery format, and AUSTRAC does not accredit training providers or courses. What matters is whether your chosen method produces the specific evidence an inspector expects to see.
| Delivery method | Retention strength | Minimum evidence produced |
|---|---|---|
| E-learning modules | Consistent, scalable | Completion timestamp, quiz score, module version |
| Instructor-led sessions | Strong for complex scenarios | Attendance log, facilitator notes, assessment outcome |
| On-the-job coaching | High for practical skills | Manager attestation, coaching log, competency sign-off |
| Blended (e-learning plus workshop) | Strongest overall | All of the above, cross-referenced by date |
E-learning scales well across multiple offices and is easy to standardise, but it can slide into passive click-through unless the assessment component is genuinely scored. Instructor-led sessions handle nuanced scenario work better, particularly for high-risk role training, but they generate less consistent paperwork unless attendance and outcomes are logged every time. On-the-job coaching builds real competency fastest but is the hardest to evidence unless a manager signs off formally.
Whichever mix you choose, multilingual delivery needs the same record linkage as English-language modules. A completion record in Vietnamese or Mandarin still needs a date, a score, and a sign-off tied back to the same audit trail as everyone else’s.
Should you outsource training content, or build it yourself?
Because AUSTRAC does not accredit or approve training providers, buying an off-the-shelf course doesn’t transfer responsibility for its adequacy. You still own the outcome, which means procurement needs a checklist, not a leap of faith.
- Confirm the provider’s content reflects Australian obligations under the Act and the AML/CTF Rules 2025, not a foreign framework repackaged for local sale.
- Check the content can be customised to your own designated services and risk typologies, not just generically branded.
- Get contract terms that protect your right to the underlying evidence data, including completion records, in a format you can retain independently.
- Confirm the vendor’s obligation to update content when AUSTRAC guidance or the Rules change, and how quickly that update reaches your staff.
Standard content is usually fine for general awareness modules covering universal concepts like record-keeping basics. Bespoke modules become necessary the moment you’re training staff on scenarios specific to your risk assessment, your client base, or a designated service most off-the-shelf libraries don’t cover well.
Who needs vetting before they need training?
Training someone you haven’t vetted doesn’t discharge your obligation. Personnel due diligence and training are a pair, and AUSTRAC treats them as linked expectations, not separate boxes to tick in either order.
Before anyone in an AML/CTF role starts training, you need documented checks covering their skills, knowledge, expertise, and integrity. That means:
- Identity verification and right-to-work confirmation.
- Bankruptcy checks, handled lawfully and proportionately to the role.
- Sanctions, PEP, and adverse media screening on the individual themselves, not just your customers.
- Criminal history checks, obtained and stored in line with applicable privacy and background-check laws.
The AML/CTF compliance officer needs an additional layer above this baseline: a fit and proper assessment covering relevant experience, demonstrated integrity, independence from conflicting business interests, and freedom from conflicts that could compromise their judgement on escalation decisions.
Pro Tip: Store your vetting records and training completion records in the same reference system, cross-linked by employee ID. When an inspector asks whether a staff member was both vetted and trained for their role, you want one query to answer both questions, not two separate filing cabinets.

How do you structure a manual you can actually defend?
A workable manual skeleton follows a logical sequence an inspector can trace from obligation to evidence.
- Purpose and scope — which staff, contractors, and functions the manual covers, cross-referenced to your risk assessment.
- Governance — who owns the manual, who approves updates, and the version log format.
- Core modules — CDD/ECDD, beneficial ownership, SMR procedures, threshold reporting, sanctions screening, record-keeping.
- Role-specific modules — tailored content for high-risk functions identified in your risk assessment.
- Assessment methods — scenario exercises, quizzes, attestations, and the passing standard for each.
- Delivery and scheduling — onboarding triggers, refresher cadence, and delivery method per role.
- Record-keeping and retention — what’s stored, for how long, and in what tamper-evident format.
- Review and update log — dated entries showing every change and its link to a risk assessment revision.
A worked example makes the skeleton concrete. Take a property settlement scenario module: the objective is recognising unusual deposit or funding-source patterns during conveyancing. The core content covers CDD standards for verifying the funding source. The scenario presents a buyer offering a cash deposit inconsistent with their declared income profile. The assessment is a short written response describing the correct escalation path. The required record is a scored response, a date, and a supervisor sign-off, stored against that employee’s training file.
Every section needs a named owner and a sign-off checklist before it goes live, and every subsequent edit needs the same discipline applied to the version log.
How do you know if your training is actually working?
Delivering training isn’t the same as proving it works. Track completion rates and pass rates by role, but also watch for the metrics that reveal whether the content is genuinely landing: how often a trained staff member still misses a red flag, how long it takes to remediate a gap once identified, and whether audit findings keep repeating on the same topic year after year.
- Completion rate by role and department.
- Pass rate on scenario-based assessments, not just quiz completion.
- Any link between an incident or audit finding and a training gap.
- Time-to-remediate once a gap is identified.
Build training review into your existing compliance calendar rather than treating it as a separate annual event. When your risk assessment gets updated, that update should trigger an automatic review of training content, not a note to “look at this eventually.” Immediate retraining triggers include a new typology flagged by AUSTRAC, an internal incident revealing a knowledge gap, or a regulatory change to the Rules. Document the corrective action plan every time, with dates and named owners, because an inspector will ask what you did after you found the gap, not just whether you found it.
How AML Guard links training to the rest of your compliance program
The recurring theme in AUSTRAC’s own commentary is consistency: a training manual that names different designated services or risk typologies to your risk assessment is the fastest way to fail an audit. AML Guard was built around that exact problem. Its guided wizards produce the business-wide ML/TF risk assessment, the AML/CTF policies, the compliance action plan, and the staff training manual as one linked set, generated from the same underlying answers.
Because all four artefacts come from the same source data, a module addressing trust and company risk in a training manual matches the wording in policies and the exposure identified in the risk assessment. That alignment is what a supervisor checks first.
- Multilingual training modules with individually tracked completion records.
- A tamper-evident audit trail covering both training and CDD activity.
- Integrated risk scoring that flows directly into module prioritisation.
- A governance dashboard showing training status alongside broader compliance obligations.
None of this implies AUSTRAC endorsement of any platform. What it does is give you an organised evidence pack ready to present the day an inspector asks for one.
What compliance officers get wrong about “finishing” a training manual
The manuals that fail audits are rarely bad on the day they’re written. They fail because nobody circled back when the risk assessment changed six months later. A living manual needs an owner with a standing calendar reminder, not a project that gets closed once and forgotten.
Micro-learning beats annual marathon sessions for retention, and a five-minute scenario refresh tied to a real near-miss sticks better than a slide deck nobody remembers by March. The internal budget argument writes itself once you frame training against the cost of a failed audit finding rather than against a training line item in isolation.
How AML Guard supports a defensible training manual
Building a training manual from scratch, then keeping it aligned to your risk assessment every time something changes, is exactly the workload that turns compliance officers into overnight document controllers. AML Guard’s advantage over a downloaded template or a static course library is structural: your training manual, your policies, and your risk assessment are generated from the same guided wizard, so they can’t quietly drift apart the way separately sourced documents do.

The platform tracks completion by role, stores results in a tamper-evident audit trail, and links training status to the same governance dashboard covering your CDD and reporting obligations. If you’re a real estate agency, law firm, conveyancing practice, or trust and company service provider building this out for the first time, the AML Guard platform is worth a look before you commit to a static template. Book a demo to see how your risk assessment, policies, and training manual come together as one evidenced set, ready the day an inspector asks for it.
Sources
Recommended
- AML risk assessment template for Tranche 2 firms
- Tranche 2 AML Australia: your compliance obligations explained
- AML/CTF policy template for Tranche 2 firms
- Acceptable ID documents for Tranche 2 firms
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.