Compliance action plans for Tranche 2 firms

Compliance action plans for Tranche 2 firms

Not a statutory document. How to link each remediation task to a section 26C risk ID, keep the plan current, and hold seven years of records.

AML/CTF Compliance 11 September 2026 9 min read AML Guard

Compliance manager reviewing linked action plan records

A compliance action plan is not a statutory document. AUSTRAC does not name it in the Act or the AML/CTF Rules 2025. It is the dated, owned list that links each ML/TF risk identified in your section 26C risk assessment to a named remediation task, with an owner, a target date and evidence of completion. Without that link back to the risk assessment, it is the first thing a reviewer picks apart.


TL;DR:


AML Guard
amlguard.com.au
Make Your Action Plan Traceable
AML Guard links your risk assessment, policies and compliance action plan, with recorded reasoning, approvals and a tamper-evident audit trail.
Book a demo

Table of Contents

What is a compliance action plan under the AML/CTF regime?

An AML/CTF program legally has two components: a business-wide ML/TF risk assessment under section 26C and AML/CTF policies that manage what that assessment finds. Sections 26D and 26E, together with the AML/CTF Rules 2025, set out how those policies must respond to identified risks and how the whole program gets documented and approved. Nowhere in that structure does a “compliance action plan” appear by name.

That is exactly why one is worth building anyway. A risk assessment tells you where the exposure sits. Policies tell you how you are meant to manage it. Neither one tells a reviewer, in plain terms, what your firm is actually doing this quarter to close a specific gap, who owns that work, and when it will be finished.

Documentation obligations bind the whole exercise together. A reporting entity must have its policies documented before it provides a designated service, and any material update needs to be recorded within 14 days. Senior manager approval and governing body oversight apply to the program itself, and a credible action plan borrows that same discipline.

Reporting deadlines matter here too, because action items often exist to fix reporting gaps. Suspicious matter reports are due within 24 hours for suspected terrorism financing and within three business days for other matters; threshold transaction reports for cash transactions of $10,000 or more are due within 10 business days. Records supporting all of it, including the action plan and its evidence, need to be kept for seven years.

How do you build an action plan linked to your risk assessment?

Build the plan in a fixed sequence, working from the risk assessment outward rather than starting with a generic checklist.

  1. Extract and rank the risks. Pull every risk your section 26C assessment identified, including proliferation financing exposures, and rank them by severity and likelihood. Give each one a stable risk ID you can reference later.
  2. Write a precise remediation task for each priority risk. Vague entries like “improve CDD” do not survive scrutiny. “Introduce enhanced due diligence triggers for politically exposed persons above a $50,000 transaction threshold” does.
  3. Assign a named owner, not a team. A role and a person’s name, both. “Compliance officer, J. Nguyen” is auditable. “The compliance team” is not.
  4. Set a realistic target date and a priority rating. AUSTRAC’s risk assessment guidance expects resources applied in proportion to risk, so your highest-rated items should carry the earliest dates and the tightest monitoring.
  5. Record the exact linkage. Reference the specific risk assessment paragraph or ID and the exact clause of your AML/CTF policies that the action changes or implements.
  6. Get senior manager approval, then publish to the governing body. Capture the approver’s name, role and date of sign off, and circulate the approved plan for governance visibility.
  7. Set a monitoring cadence and an escalation rule. Decide who gets notified when an item runs overdue, and by how many days before it escalates.

Pro Tip: Number your risk IDs and action IDs with a shared prefix (R‑014 mapping to A‑014, for example). When an evaluator asks you to trace a control back to its risk, you want that answer to take five seconds, not five emails.

What fields belong in an action plan template?

A usable action item needs a fixed set of fields, every time, with no shortcuts on the ones that prove traceability.

A completeness check before you file the plan should confirm four things: every item traces to a risk, senior manager approval is recorded, evidence sits in a tamper-evident record, and any related training is scheduled where the gap calls for it.

Take a conveyancing firm whose risk assessment flags weak beneficial ownership verification on trust‑purchased properties as a moderate‑to‑high risk (R‑009). The linked action (A‑009) reads: “Implement corporate trustee ACN lookup and officer review for all trust‑purchased matters.” Owner: settlement manager, T. Ahmed. Target date: 30 September 2026. Evidence: screenshot of completed lookup filed against the matter ID. That one line, filled in properly, is what a reviewer wants to see against every flagged risk.

How do you keep the action plan current and audit-ready?

Treat the plan as a living document, not a file you produce once and forget.

Pro Tip: Store completed evidence the moment an action closes, not at year end. Reconstructing six months of sign offs from memory is exactly the scramble a tamper-evident record is meant to prevent.

Common problems AML Guard sees in action plans

AML Guard builds the compliance action plan as one of four linked artefacts, alongside the risk assessment, the AML/CTF policies and the staff training manual, generated from the same underlying answers so all three agree with each other.

Four linked AML compliance program artefacts

The recurring failures are consistent: action items with no risk ID attached, approvals missing a name or date, and evidence that was promised but never filed anywhere retrievable. Recorded reasoning behind each risk rating, named-owner workflows and a tamper-evident audit trail remove most of that friction before an evaluator ever asks the question.

Why most firms get the action plan backwards

Most guidance on this topic treats the action plan as paperwork you produce to look organised. That gets the order wrong. The plan should be the most argued-over document in your program, because it is where risk theory meets a real person doing a real task by a real date.

The conventional advice, write a checklist and tick it off, fails because a checklist has no memory of why each item exists. The moment your risk profile shifts, a plain checklist goes stale and nobody notices. A properly linked action plan, where every item still points back to a risk ID, tells you immediately which parts of your remediation work are obsolete and which still matter.

Prioritise the linkage before the polish. A plan with five items, each traceable to a rated risk with a real owner and date, beats a twenty-item plan that reads well but connects to nothing. That is the standard an AUSTRAC review actually tests, and it is the standard AML Guard was built to produce by default.

Turning your action plan into a working system

Spreadsheets can hold an action plan for a while. They stop holding it the moment your risk assessment changes and nobody updates the twelve action items that referenced the old rating.

AML Guard action plan linking each task to its risk ID and owner

AML Guard generates the compliance action plan alongside your ML/TF risk assessment and AML/CTF policies from one guided set of answers, so all three stay consistent instead of drifting apart over time. Risk scoring comes with the reasoning recorded, approval workflows capture the named owner and date for every sign off, and a seven-year tamper-evident audit trail keeps evidence tied to its action ID without manual filing. For agencies running listings through REX CRM, compliance status indicators surface against each listing without ever pushing CDD data across systems.

If your current plan is a document nobody has opened since it was approved, that is worth fixing before your next review. Book a demo through AML Guard and see how the four artefacts, including your action plan, come out linked from the start.

Where to check the source obligations

Sources

FAQ

No. The Act and Rules require a section 26C risk assessment and AML/CTF policies. An action plan is a practical tool that links the two, not a separate statutory document.

What makes an action plan credible to an AUSTRAC reviewer?

Each item must trace to a specific risk ID from the risk assessment, name an accountable owner, carry a target date, and store evidence of completion in a retrievable record.

How often should the action plan be updated?

Update it whenever a new risk, service or control failure emerges, and document any material change within 14 days, matching the update rule that applies to AML/CTF policies.

Who needs to approve the action plan?

A senior manager should approve the plan and material updates to it, with the governing body maintaining oversight of progress and outstanding items.

Can AML Guard generate a compliance action plan automatically?

AML Guard produces the action plan alongside the risk assessment, AML/CTF policies and staff training manual from one linked set of answers, so the documents stay consistent with each other.

See How AML Guard Works

Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo
This article is for general information purposes only and does not constitute legal advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.
Last reviewed: 11 September 2026.