
A compliance action plan is not a statutory document. AUSTRAC does not name it in the Act or the AML/CTF Rules 2025. It is the dated, owned list that links each ML/TF risk identified in your section 26C risk assessment to a named remediation task, with an owner, a target date and evidence of completion. Without that link back to the risk assessment, it is the first thing a reviewer picks apart.
TL;DR:
- An effective action plan must link each remediation task directly to a specific risk ID from the risk assessment, with clear ownership, targeted dates, and supporting evidence.
- The plan should be built by extracting and prioritizing risks in order, then drafting precise tasks assigned to named individuals, not teams, and referencing relevant policy clauses.
- Regular updates are essential when risks change, new services are introduced, or controls fail, with documentation required within 14 days of any material modification.
- Approval from a senior manager and oversight by the governing body are necessary for both the plan and its updates, ensuring accountability and review readiness.
- Using a linked, automated system like AML Guard helps maintain plan consistency, proper traceability, and easy retrieval of evidence for audits and evaluations.
Table of Contents
- What is a compliance action plan under the AML/CTF regime?
- How do you build an action plan linked to your risk assessment?
- What fields belong in an action plan template?
- How do you keep the action plan current and audit-ready?
- Common problems AML Guard sees in action plans
- Why most firms get the action plan backwards
- Turning your action plan into a working system
- Where to check the source obligations
- Sources
- FAQ
What is a compliance action plan under the AML/CTF regime?
An AML/CTF program legally has two components: a business-wide ML/TF risk assessment under section 26C and AML/CTF policies that manage what that assessment finds. Sections 26D and 26E, together with the AML/CTF Rules 2025, set out how those policies must respond to identified risks and how the whole program gets documented and approved. Nowhere in that structure does a “compliance action plan” appear by name.
That is exactly why one is worth building anyway. A risk assessment tells you where the exposure sits. Policies tell you how you are meant to manage it. Neither one tells a reviewer, in plain terms, what your firm is actually doing this quarter to close a specific gap, who owns that work, and when it will be finished.
Documentation obligations bind the whole exercise together. A reporting entity must have its policies documented before it provides a designated service, and any material update needs to be recorded within 14 days. Senior manager approval and governing body oversight apply to the program itself, and a credible action plan borrows that same discipline.
Reporting deadlines matter here too, because action items often exist to fix reporting gaps. Suspicious matter reports are due within 24 hours for suspected terrorism financing and within three business days for other matters; threshold transaction reports for cash transactions of $10,000 or more are due within 10 business days. Records supporting all of it, including the action plan and its evidence, need to be kept for seven years.
- Section 26C risk assessment: identifies and rates ML/TF and proliferation financing risks
- AML/CTF policies: the documented controls that manage those rated risks
- Compliance action plan: the dated, owned bridge between the two
- Senior manager and governing body: approve and oversee both the program and material changes to it
How do you build an action plan linked to your risk assessment?
Build the plan in a fixed sequence, working from the risk assessment outward rather than starting with a generic checklist.
- Extract and rank the risks. Pull every risk your section 26C assessment identified, including proliferation financing exposures, and rank them by severity and likelihood. Give each one a stable risk ID you can reference later.
- Write a precise remediation task for each priority risk. Vague entries like “improve CDD” do not survive scrutiny. “Introduce enhanced due diligence triggers for politically exposed persons above a $50,000 transaction threshold” does.
- Assign a named owner, not a team. A role and a person’s name, both. “Compliance officer, J. Nguyen” is auditable. “The compliance team” is not.
- Set a realistic target date and a priority rating. AUSTRAC’s risk assessment guidance expects resources applied in proportion to risk, so your highest-rated items should carry the earliest dates and the tightest monitoring.
- Record the exact linkage. Reference the specific risk assessment paragraph or ID and the exact clause of your AML/CTF policies that the action changes or implements.
- Get senior manager approval, then publish to the governing body. Capture the approver’s name, role and date of sign off, and circulate the approved plan for governance visibility.
- Set a monitoring cadence and an escalation rule. Decide who gets notified when an item runs overdue, and by how many days before it escalates.
Pro Tip: Number your risk IDs and action IDs with a shared prefix (R‑014 mapping to A‑014, for example). When an evaluator asks you to trace a control back to its risk, you want that answer to take five seconds, not five emails.
What fields belong in an action plan template?
A usable action item needs a fixed set of fields, every time, with no shortcuts on the ones that prove traceability.
- Action ID — a unique reference, ideally matching its linked risk ID
- Linked risk ID — the exact reference from your section 26C risk assessment
- Remediation description — the specific control, procedure or training being implemented
- Owner — named individual and role
- Priority — high, medium or low, set proportionate to the risk rating
- Target date — a real date, not a quarter or “ongoing”
- Evidence required — the document ID or storage location that will prove completion
- Status — open, in progress, complete or overdue
- Completion date and approver signature/date — who signed off, and when
A completeness check before you file the plan should confirm four things: every item traces to a risk, senior manager approval is recorded, evidence sits in a tamper-evident record, and any related training is scheduled where the gap calls for it.
Take a conveyancing firm whose risk assessment flags weak beneficial ownership verification on trust‑purchased properties as a moderate‑to‑high risk (R‑009). The linked action (A‑009) reads: “Implement corporate trustee ACN lookup and officer review for all trust‑purchased matters.” Owner: settlement manager, T. Ahmed. Target date: 30 September 2026. Evidence: screenshot of completed lookup filed against the matter ID. That one line, filled in properly, is what a reviewer wants to see against every flagged risk.
How do you keep the action plan current and audit-ready?
Treat the plan as a living document, not a file you produce once and forget.
- Update triggers. A new designated service, a new risk exposure, a regulatory change or a failed control should all trigger a plan update, documented within the same 14 day window that applies to policy changes.
- Reporting cadence. The compliance officer should report progress to the senior manager and governing body on a set schedule, quarterly at minimum, covering overdue items, closed items and any risk rating changes.
- Evidence discipline. Every completed action needs its evidence linked to its Action ID and stored in a tamper-evident system, retained for seven years alongside the rest of your program records.
- Presenting to an evaluator. During an independent evaluation, which AUSTRAC expects at least every three years, walk the evaluator from risk ID to action ID to evidence file in one unbroken chain.
Pro Tip: Store completed evidence the moment an action closes, not at year end. Reconstructing six months of sign offs from memory is exactly the scramble a tamper-evident record is meant to prevent.
Common problems AML Guard sees in action plans
AML Guard builds the compliance action plan as one of four linked artefacts, alongside the risk assessment, the AML/CTF policies and the staff training manual, generated from the same underlying answers so all three agree with each other.

The recurring failures are consistent: action items with no risk ID attached, approvals missing a name or date, and evidence that was promised but never filed anywhere retrievable. Recorded reasoning behind each risk rating, named-owner workflows and a tamper-evident audit trail remove most of that friction before an evaluator ever asks the question.
Why most firms get the action plan backwards
Most guidance on this topic treats the action plan as paperwork you produce to look organised. That gets the order wrong. The plan should be the most argued-over document in your program, because it is where risk theory meets a real person doing a real task by a real date.
The conventional advice, write a checklist and tick it off, fails because a checklist has no memory of why each item exists. The moment your risk profile shifts, a plain checklist goes stale and nobody notices. A properly linked action plan, where every item still points back to a risk ID, tells you immediately which parts of your remediation work are obsolete and which still matter.
Prioritise the linkage before the polish. A plan with five items, each traceable to a rated risk with a real owner and date, beats a twenty-item plan that reads well but connects to nothing. That is the standard an AUSTRAC review actually tests, and it is the standard AML Guard was built to produce by default.
Turning your action plan into a working system
Spreadsheets can hold an action plan for a while. They stop holding it the moment your risk assessment changes and nobody updates the twelve action items that referenced the old rating.

AML Guard generates the compliance action plan alongside your ML/TF risk assessment and AML/CTF policies from one guided set of answers, so all three stay consistent instead of drifting apart over time. Risk scoring comes with the reasoning recorded, approval workflows capture the named owner and date for every sign off, and a seven-year tamper-evident audit trail keeps evidence tied to its action ID without manual filing. For agencies running listings through REX CRM, compliance status indicators surface against each listing without ever pushing CDD data across systems.
If your current plan is a document nobody has opened since it was approved, that is worth fixing before your next review. Book a demo through AML Guard and see how the four artefacts, including your action plan, come out linked from the start.
Where to check the source obligations
- AML/CTF program overview — AUSTRAC
- Anti‑Money Laundering and Counter‑Terrorism Financing Rules 2025 — legislation.gov.au
- Real estate designated services — AUSTRAC
Sources
- Real estate designated services | AUSTRAC
- Your AML/CTF program overview | AUSTRAC
- AML/CTF Rules 2025 | Federal Register of Legislation
FAQ
Is a compliance action plan a legal requirement under the AML/CTF Act?
No. The Act and Rules require a section 26C risk assessment and AML/CTF policies. An action plan is a practical tool that links the two, not a separate statutory document.
What makes an action plan credible to an AUSTRAC reviewer?
Each item must trace to a specific risk ID from the risk assessment, name an accountable owner, carry a target date, and store evidence of completion in a retrievable record.
How often should the action plan be updated?
Update it whenever a new risk, service or control failure emerges, and document any material change within 14 days, matching the update rule that applies to AML/CTF policies.
Who needs to approve the action plan?
A senior manager should approve the plan and material updates to it, with the governing body maintaining oversight of progress and outstanding items.
Can AML Guard generate a compliance action plan automatically?
AML Guard produces the action plan alongside the risk assessment, AML/CTF policies and staff training manual from one linked set of answers, so the documents stay consistent with each other.
Recommended
- Tranche 2 AML Australia: your compliance obligations explained
- AML/CTF policy template for Tranche 2 firms
- Tranche 2 customer due diligence in Australia
- AML/CTF Program Documents for Tranche 2
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.