Which AML/CTF program template should you use in 2026?

Which AML/CTF program template should you use in 2026?

Discover which AML/CTF program template to use in 2026. Learn how to customize AUSTRAC's starter kit for effective compliance.

AML/CTF Compliance 24 August 2026 8 min read AML Guard

Use an official AUSTRAC program starter kit as your authoritative Australian template, then customise it against your own ML/TF risk assessment. Do not lodge or operate a starter kit unchanged.

Three facts govern this decision:

Key Takeaways

A compliant AML/CTF program starts with an AUSTRAC starter kit customised against your own risk assessment, then becomes real only once it’s embedded into daily workflows and provable through records.

Point Details
Start with the official kit Download the relevant AUSTRAC starter kit for your sector rather than a generic online template.
Risk assessment drives everything Set CDD thresholds and EDD triggers from your ML/TF risk assessment findings, not from guesswork.
Build one integrated document Follow the amended framework’s outcomes-focused structure instead of the old Part A/Part B split.
Prove implementation, not just drafting Keep version logs, training records, and sign-offs so a reviewer sees the program in use.
Operationalise with AML Guard AML Guard turns program documents into live workflows, covering CDD, screening, beneficial ownership tracing, and audit trails for Tranche 2 entities.

Table of Contents

Where to find AUSTRAC starter kits and other Australian templates

AUSTRAC publishes sector-specific starter kits for accountants, real estate agents, conveyancers, and legal practitioners, each built around the same statutory skeleton but weighted toward that sector’s designated services. Every kit bundles a policy template, a risk assessment worksheet, and customer due diligence appendices covering identity verification and record-keeping.

Worth pairing with the official kits:

None of these replace legal advice for complex structures, but together they give a reporting entity everything needed to draft a defensible first version.

How do you customise a starter kit into a working program?

Turning a downloaded template into an operational document is a project, not a copy-paste exercise. Follow this sequence:

  1. Map your designated services. List every Table 5 or Table 6 service you provide and how you deliver it (in person, online, via a portal), then align each starter kit section to that list.
  2. Run the ML/TF risk assessment first. Everything downstream, your CDD thresholds, enhanced due diligence (EDD) triggers, and monitoring rules, should trace back to specific findings in that assessment.
  3. Assign ownership and get sign-off. Name your AML/CTF compliance officer, brief senior management, and record their formal approval of the finished document.
  4. Embed procedures into daily workflows. Build the CDD steps into onboarding, not just into a PDF nobody opens after week one.
  5. Keep a version log. Record every amendment, who approved it, and why, alongside training completion records for staff who work under the program.

Pro Tip: Keep a one-page “evidence trail” spreadsheet that links every policy clause back to the risk assessment finding that justifies it. When AUSTRAC or an independent reviewer asks why a control exists, you point to a row, not a memory.

What must the program actually contain?

AUSTRAC’s guidance on developing an AML/CTF program sets out the non-negotiable components, and the amended framework expects them written as one integrated document rather than split across legacy parts.

ML/TF risk assessment. Document the scope of your business, the likelihood and impact of money laundering and terrorism financing across your customer types, delivery channels, and jurisdictions, and set a review trigger (new service line, new customer segment, regulatory change) rather than a fixed annual date alone.

Diagram of AML risk assessment components

Governance and oversight. The board or senior management must approve the program and understand their obligations under it. The AML/CTF compliance officer needs a documented mandate: what they can decide alone, and what needs escalation.

Customer due diligence and reporting. This covers identity verification standards, beneficial ownership tracing for companies, trusts and SMSFs, politically exposed person (PEP) screening, and the workflow for lodging a suspicious matter report when something doesn’t check out.

Hands holding ID near verification device

Monitoring, records, and review. AUSTRAC expects ongoing transaction monitoring tuned to your risk assessment, a seven-year record-keeping standard, and periodic independent review of the whole program’s effectiveness.

Every one of these controls should cite the risk assessment finding it responds to. A CDD threshold with no risk rationale behind it is exactly the kind of gap an independent reviewer flags first.

A template structure you can build from today

Rather than retaining the old Part A/Part B labelling, structure your program as one integrated document under these headings:

If your existing program still runs the legacy Part A/Part B split, you don’t need to rewrite it overnight, but new content should be drafted against this integrated structure so the transition is straightforward when you next revise it. AUSTRAC’s Tranche 2 document guidance is a useful reference point for what a finished set of documents looks like in practice.

Sense-check each section against this short list before calling the document final:

Building a realistic implementation timeline

A template is only as good as the project plan behind it. Professional bodies including Chartered Accountants ANZ have published realistic project plans with milestones that smaller firms can scale down without losing rigour.

  1. Weeks 0 to 2: Scope your designated services and appoint your compliance officer.
  2. Weeks 2 to 6: Complete the risk assessment and draft policies against it.
  3. Weeks 6 to 10: Configure systems, train staff, and set up record-keeping.
  4. Weeks 10 to 14: Run an independent review and secure board approval.
Phase Weeks Primary owner Common roadblock
Scope and appoint 0 to 2 Principal or practice manager Unclear designated services list
Risk assessment and drafting 2 to 6 Compliance officer Missing customer or transaction data
Systems and training 6 to 10 Compliance officer and IT lead Competing operational priorities
Review and approval 10 to 14 Senior management or board Reviewer availability

Data gaps are the most common cause of delay. If you can’t pull a clean list of customer types or transaction volumes in week one, fix that before drafting a single policy clause.

What actually makes a template fail in practice

Most programs don’t fail on paper, they fail in the drawer. A beautifully worded risk assessment means nothing if the person onboarding a trust client has never seen it and can’t name a beneficial ownership trigger when one appears.

The pattern repeats across property, legal, and accounting files: a template gets approved, then operational reality drifts from it within months. Beneficial ownership evidence for trusts is a frequent failure point, since discretionary trusts and SMSFs rarely present a tidy ownership chain, and enhanced due diligence triggers in property transactions get missed when nobody’s watching for cash-heavy buyers or rushed settlements. Status flags synced to the systems your team already uses, and a tamper-evident audit trail that survives an independent review, close that gap far better than a document sitting in a shared drive.

Turning your program document into working controls

AUSTRAC starter kits give you the words. Making those words operational, verified identities, screened beneficial owners, logged suspicious matter reports, is a separate job, and it’s the one most firms underestimate.

AML Guard is built to close that gap for Australian Tranche 2 reporting entities. Guided wizards produce all four program artefacts as one linked set rather than four separate documents: the business-wide ML/TF risk assessment, the AML/CTF policies, the compliance action plan, and the staff training manual. Because they are generated from the same answers, the policies match the risk assessment and the training manual matches the policies, which is the internal consistency a supervisor checks and the one thing a downloaded template cannot give you. Around them, identity verification, PEP and sanctions screening, and beneficial ownership tracing across companies, trusts and SMSFs run against every customer, not just the ones someone remembers to check.

AML Guard

Status indicators sync to REX CRM so your team sees compliance progress against a listing without duplicating data entry, and a client-pays option lets a transaction party fund their own verification, with the fee credited back against your subscription. Multilingual training records and a seven-year tamper-evident audit trail mean an independent reviewer gets a complete evidence trail instead of a folder of loose documents. There’s no self-service sign-up: firms start by booking a demo so their tenant can be configured to their actual designated services and risk profile.

Sources

See How AML Guard Works

Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo
This article is for general information purposes only and does not constitute legal advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.
Last reviewed: 24 August 2026.