Audit-ready AML files for an AUSTRAC request

Audit-ready AML files for an AUSTRAC request

What to have ready when AUSTRAC asks for your AML/CTF documents or an independent evaluator starts work: approvals, decision reasoning, records and a plan.

AML/CTF Compliance 1 October 2026 8 min read AML Guard

Reviewer examining anonymised CDD case files

Being audit ready means having a senior-manager-approved ML/TF risk assessment and matching AML/CTF policies, an appointed compliance officer, and indexed customer due diligence files that show what decision was made and why. You also need evidence of your independent evaluation schedule, set at least once every 3 years under section 26F(4)(f), and a clear understanding of how AUSTRAC asks: a written notice under section 26Q for your program documents, and its wider information-gathering powers.


TL;DR:


AML Guard
Make Audit Evidence Easier to Manage
AML Guard links your AML/CTF program artefacts, CDD records, reporting workflows and 8-year tamper-evident audit trail.
Book a demo

Table of Contents

Audit-ready checklist: step-by-step actions your team must complete

Preparation is a sequence, not a single task. Work through it methodically and you reduce the chance of gaps surfacing when a notice lands.

  1. Run a gap analysis. Compare your current risk assessment and AML/CTF policies against actual operations, and confirm both carry senior manager approval and clean version history.
  2. Assemble your document pack. Gather approved program documents, independent evaluation reports, a sample of CDD files, SMR and TTR registers, transaction records and training completion evidence.
  3. Test a sample. Pick a handful of customer files at random, reconstruct the due diligence decision from the paper trail, and check whether the rationale is legible to someone outside the file.
  4. Confirm sign-off and escalation. Decide who reviews the pack before it leaves the business and who is the single point of contact for any external enquiry.

Sample-testing works best when it mimics what an evaluator or AUSTRAC officer would actually do: pull a file, ask why a decision was made, and see if the answer is on paper rather than in someone’s memory.

Pro Tip: Keep a running folder of “hard case” CDD files, the ones that needed judgement calls, since these are the files an evaluator or AUSTRAC will gravitate towards.

Hard case CDD files selected for audit review

What AUSTRAC expects you to keep and how to present it

Record keeping is not an afterthought to the program; it is the evidence that the program exists. AUSTRAC’s record keeping guidance sets out what reporting entities need to retain to demonstrate compliance.

The Act sets seven years, but not from the same day for every record. Program records (including training logs and evaluation reports) are kept until seven years after they stop being relevant (section 116), CDD records until seven years after the business relationship ends or the occasional transaction is completed (section 111), and transaction records for seven years from when they are made (section 107). Presentation matters as much as retention: AUSTRAC expects records kept in their original format (or the format you usually use), and sensitive records stored securely with access limited to authorised staff. Index them for quick retrieval and keep an audit trail of changes. A folder of scanned PDFs with no index is hard to defend the day a request arrives.

Governance and program design: what to evidence to show the program is effective

A program that exists only on paper will not survive scrutiny. The Act ties it to governance: the governing body must exercise ongoing oversight (section 26H), a senior manager must approve the risk assessment and policies (section 26P), and an AML/CTF compliance officer must be designated to run the day-to-day work (section 26J).

The link between these documents matters more than any one of them alone. A risk assessment that flags high-risk customer types but policies that never mention enhanced due diligence for them is the kind of mismatch a reviewer looks for. Under section 26G of the AML/CTF Act, failing to comply with your own AML/CTF policies is a civil penalty provision, so alignment between what is written and what staff do is not optional paperwork; it is the substance of the obligation.

Preparing for an independent evaluation: scope, access and responding to findings

Independent evaluation is a separate duty from ongoing supervision, and it needs its own preparation cycle. AUSTRAC’s guidance on independent evaluations explains what the Rules require: the evaluation must test your risk assessment, your policies and whether your controls are actually implemented, not just whether the documents exist.

  1. Confirm scope. The evaluation should cover the risk assessment, policies and operational testing of controls, at a frequency set in your own policies of at least once every 3 years.
  2. Prepare access. Evaluators commonly request the program documents, a sample of CDD files, transaction records, training logs and prior evaluation reports.
  3. Document evaluator selection. Keep a record of why a particular evaluator was chosen, their independence from the function being reviewed, and the methodology they used.
  4. Plan for findings. The Rules require a written report delivered to the governing body and to the senior manager who approves your program, and your policies must say how you will respond to it, including updating them where the findings are adverse.

Pro Tip: Treat adverse findings as a governance event, not just a compliance task: log the finding, the fix and the date, and put it in front of the governing body at the next meeting.

AUSTRAC supervisory powers and a practical response protocol

AUSTRAC does not run a routine annual audit. It supervises on an ongoing basis and can ask for your AML/CTF program documents by written notice under section 26Q. Its information-gathering powers also include notices to give information or produce documents, and compulsory examinations under section 172A. None of these runs to a calendar, so readiness has to be continuous rather than timed to a date.

How a compliance platform can reduce response time and improve evidence quality

A common failure point is inconsistency: a risk assessment that says one thing, policies that say another, and training that reflects neither. AML Guard generates the risk assessment, AML/CTF policies, compliance action plan and staff training manual as one linked set from the same inputs, so the documents do not contradict each other.

A compliance officer’s day: quick checks the week after an AUSTRAC notice

Confirm the exact scope of the request before touching a file. Pull the relevant samples, lock the originals so nothing changes mid-response, and note who to call if a gap turns up. The pitfalls that repeat are mismatched policy and training wording, missing decision rationale in CDD files, and sloppy version control. A weekly index health check and an annual tabletop exercise for the governing body catch most of it early.

How AML Guard helps you be audit ready

Firms preparing for AUSTRAC supervision or an independent evaluation need documents that agree with each other and files that show their reasoning, not just a stack of paperwork. AML Guard builds the risk assessment, AML/CTF policies, compliance action plan and training manual from one linked set of answers, runs CDD and enhanced CDD end to end, and resolves beneficial ownership through a company’s ACN (with trusts and SMSFs reached via their corporate trustee’s own ACN determination). Multilingual training records and an 8-year tamper-evident audit trail sit behind every decision, with an officer approving each determination before CDD proceeds.

Sources

FAQ

What needs to be reported to AUSTRAC?

Reporting entities must give suspicious matter reports (SMRs) under section 41 within 3 business days of forming the suspicion, or 24 hours for terrorism financing, and threshold transaction reports for transactions involving physical currency of $10,000 or more. Both are ongoing obligations, not something reserved for an audit period.

Which changes must be advised to AUSTRAC within 14 days?

Two common ones: a change to your enrolment details of a kind the AML/CTF Rules specify must be advised within 14 days of the change (section 51F), and a newly designated AML/CTF compliance officer must be notified within 14 days of being designated (section 26M). There is no 14-day rule for acting on an independent evaluation; your policies set how you respond to the report.

What are the AUSTRAC record keeping requirements?

Seven years, counted from different points: program records (risk assessment, policies, training logs, evaluation reports) until seven years after they stop being relevant, CDD records until seven years after the business relationship ends or the occasional transaction is completed, and transaction records for seven years from when they are made. AUSTRAC’s guidance also expects records in their original format (or the format you usually use) and sensitive records stored securely.

See How AML Guard Works

Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo
This article is for general information purposes only and does not constitute legal advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.
Last reviewed: 1 October 2026.