
Being audit ready means having a senior-manager-approved ML/TF risk assessment and matching AML/CTF policies, an appointed compliance officer, and indexed customer due diligence files that show what decision was made and why. You also need evidence of your independent evaluation schedule, set at least once every 3 years under section 26F(4)(f), and a clear understanding of how AUSTRAC asks: a written notice under section 26Q for your program documents, and its wider information-gathering powers.
TL;DR:
- A thorough gap analysis and a well-organised document pack are essential to demonstrate compliance during an audit or AUSTRAC request.
- Keep records for the periods the Act sets (seven years, counted differently for program, CDD and transaction records) and store them so you can find and produce them quickly.
- Governance evidence such as signed approvals, minutes, and version-controlled policies are crucial to prove program oversight and effective implementation.
- Independent evaluations must cover risk assessment, policies, and controls at least once every three years, and your policies must say how you respond to the findings.
- Using an integrated compliance platform like AML Guard keeps documents consistent with each other, captures decision rationale, and maintains a secure, auditable trail.
Table of Contents
- Audit-ready checklist: step-by-step actions your team must complete
- What AUSTRAC expects you to keep and how to present it
- Governance and program design: what to evidence to show the program is effective
- Preparing for an independent evaluation: scope, access and responding to findings
- AUSTRAC supervisory powers and a practical response protocol
- How a compliance platform can reduce response time and improve evidence quality
- A compliance officer’s day: quick checks the week after an AUSTRAC notice
- How AML Guard helps you be audit ready
- Sources
- FAQ
Audit-ready checklist: step-by-step actions your team must complete
Preparation is a sequence, not a single task. Work through it methodically and you reduce the chance of gaps surfacing when a notice lands.
- Run a gap analysis. Compare your current risk assessment and AML/CTF policies against actual operations, and confirm both carry senior manager approval and clean version history.
- Assemble your document pack. Gather approved program documents, independent evaluation reports, a sample of CDD files, SMR and TTR registers, transaction records and training completion evidence.
- Test a sample. Pick a handful of customer files at random, reconstruct the due diligence decision from the paper trail, and check whether the rationale is legible to someone outside the file.
- Confirm sign-off and escalation. Decide who reviews the pack before it leaves the business and who is the single point of contact for any external enquiry.
Sample-testing works best when it mimics what an evaluator or AUSTRAC officer would actually do: pull a file, ask why a decision was made, and see if the answer is on paper rather than in someone’s memory.
Pro Tip: Keep a running folder of “hard case” CDD files, the ones that needed judgement calls, since these are the files an evaluator or AUSTRAC will gravitate towards.

What AUSTRAC expects you to keep and how to present it
Record keeping is not an afterthought to the program; it is the evidence that the program exists. AUSTRAC’s record keeping guidance sets out what reporting entities need to retain to demonstrate compliance.
- Risk assessment, AML/CTF policies, and their approval and version history.
- CDD records, including identity verification, screening outcomes and the reasoning behind each decision.
- Transaction records sufficient to reconstruct a customer’s activity.
- Training completion logs and independent evaluation reports.
The Act sets seven years, but not from the same day for every record. Program records (including training logs and evaluation reports) are kept until seven years after they stop being relevant (section 116), CDD records until seven years after the business relationship ends or the occasional transaction is completed (section 111), and transaction records for seven years from when they are made (section 107). Presentation matters as much as retention: AUSTRAC expects records kept in their original format (or the format you usually use), and sensitive records stored securely with access limited to authorised staff. Index them for quick retrieval and keep an audit trail of changes. A folder of scanned PDFs with no index is hard to defend the day a request arrives.
Governance and program design: what to evidence to show the program is effective
A program that exists only on paper will not survive scrutiny. The Act ties it to governance: the governing body must exercise ongoing oversight (section 26H), a senior manager must approve the risk assessment and policies (section 26P), and an AML/CTF compliance officer must be designated to run the day-to-day work (section 26J).
- Governing body minutes showing review and oversight of the AML/CTF program.
- Signed senior manager approval of the risk assessment (reviewed at least every 3 years and after significant change under section 26D) and the AML/CTF policies.
- Version-controlled policy documents that trace back to the current risk assessment, with documented reasoning wherever a control deviates from the standard approach.
- Training completion registers tied to the roles and risks each staff member actually handles.
The link between these documents matters more than any one of them alone. A risk assessment that flags high-risk customer types but policies that never mention enhanced due diligence for them is the kind of mismatch a reviewer looks for. Under section 26G of the AML/CTF Act, failing to comply with your own AML/CTF policies is a civil penalty provision, so alignment between what is written and what staff do is not optional paperwork; it is the substance of the obligation.
Preparing for an independent evaluation: scope, access and responding to findings
Independent evaluation is a separate duty from ongoing supervision, and it needs its own preparation cycle. AUSTRAC’s guidance on independent evaluations explains what the Rules require: the evaluation must test your risk assessment, your policies and whether your controls are actually implemented, not just whether the documents exist.
- Confirm scope. The evaluation should cover the risk assessment, policies and operational testing of controls, at a frequency set in your own policies of at least once every 3 years.
- Prepare access. Evaluators commonly request the program documents, a sample of CDD files, transaction records, training logs and prior evaluation reports.
- Document evaluator selection. Keep a record of why a particular evaluator was chosen, their independence from the function being reviewed, and the methodology they used.
- Plan for findings. The Rules require a written report delivered to the governing body and to the senior manager who approves your program, and your policies must say how you will respond to it, including updating them where the findings are adverse.
Pro Tip: Treat adverse findings as a governance event, not just a compliance task: log the finding, the fix and the date, and put it in front of the governing body at the next meeting.
AUSTRAC supervisory powers and a practical response protocol
AUSTRAC does not run a routine annual audit. It supervises on an ongoing basis and can ask for your AML/CTF program documents by written notice under section 26Q. Its information-gathering powers also include notices to give information or produce documents, and compulsory examinations under section 172A. None of these runs to a calendar, so readiness has to be continuous rather than timed to a date.
- Acknowledge the notice promptly and read the scope carefully before assembling anything.
- Assign a single internal contact so the response is centralised, not scattered across departments.
- Build an indexed pack that answers exactly what was asked, logging versions and dates as you go.
- Preserve original formats and keep a notes trail showing who did what, and when, so the response itself demonstrates control.
- Escalate to the senior manager or governing body if the request touches program design rather than a single file.
How a compliance platform can reduce response time and improve evidence quality
A common failure point is inconsistency: a risk assessment that says one thing, policies that say another, and training that reflects neither. AML Guard generates the risk assessment, AML/CTF policies, compliance action plan and staff training manual as one linked set from the same inputs, so the documents do not contradict each other.
- Officer-approval workflows mean a human signs off on each CDD determination before it proceeds, so the rationale behind a decision is captured rather than assumed.
- Every decision sits in an 8-year tamper-evident audit trail, above the Act’s seven-year minimum.
- This is one example of a purpose-built toolset; firms should weigh solutions against their own size, customer base and risk profile before choosing.
A compliance officer’s day: quick checks the week after an AUSTRAC notice
Confirm the exact scope of the request before touching a file. Pull the relevant samples, lock the originals so nothing changes mid-response, and note who to call if a gap turns up. The pitfalls that repeat are mismatched policy and training wording, missing decision rationale in CDD files, and sloppy version control. A weekly index health check and an annual tabletop exercise for the governing body catch most of it early.
How AML Guard helps you be audit ready
Firms preparing for AUSTRAC supervision or an independent evaluation need documents that agree with each other and files that show their reasoning, not just a stack of paperwork. AML Guard builds the risk assessment, AML/CTF policies, compliance action plan and training manual from one linked set of answers, runs CDD and enhanced CDD end to end, and resolves beneficial ownership through a company’s ACN (with trusts and SMSFs reached via their corporate trustee’s own ACN determination). Multilingual training records and an 8-year tamper-evident audit trail sit behind every decision, with an officer approving each determination before CDD proceeds.
- Review the features that map to program documentation, CDD and audit trail requirements.
- Check current pricing for the Platform subscription and the Standard Individual, High-Risk Individual and Company / Trust services.
- Book a demo to see a configuration tailored to your sector and risk profile.
Sources
- Your AML/CTF program overview | AUSTRAC
- Record keeping overview | AUSTRAC
- Step 5: Conduct an independent evaluation | AUSTRAC
- New information gathering powers | AUSTRAC
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
FAQ
What needs to be reported to AUSTRAC?
Reporting entities must give suspicious matter reports (SMRs) under section 41 within 3 business days of forming the suspicion, or 24 hours for terrorism financing, and threshold transaction reports for transactions involving physical currency of $10,000 or more. Both are ongoing obligations, not something reserved for an audit period.
Which changes must be advised to AUSTRAC within 14 days?
Two common ones: a change to your enrolment details of a kind the AML/CTF Rules specify must be advised within 14 days of the change (section 51F), and a newly designated AML/CTF compliance officer must be notified within 14 days of being designated (section 26M). There is no 14-day rule for acting on an independent evaluation; your policies set how you respond to the report.
What are the AUSTRAC record keeping requirements?
Seven years, counted from different points: program records (risk assessment, policies, training logs, evaluation reports) until seven years after they stop being relevant, CDD records until seven years after the business relationship ends or the occasional transaction is completed, and transaction records for seven years from when they are made. AUSTRAC’s guidance also expects records in their original format (or the format you usually use) and sensitive records stored securely.
Recommended
- Tranche 2 customer due diligence in Australia
- Tranche 2 AML Australia: your compliance obligations explained
- AML/CTF Program Documents for Tranche 2
- Acceptable ID documents for Tranche 2 firms
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.