Getting compliant

Your AML/CTF obligations, in plain English

True Comply · · 6 min read

← Back to Insights
An overhead view of a timber desk with printed forms, a pen and two small potted plants.

The obligations aren't as mysterious as they sound

For businesses newly captured under Tranche 2, the AML/CTF regime can look like an alphabet soup of acronyms. Underneath, the obligations are a connected set of practical steps. Here is what each one means in plain English.

1. Enrol with AUSTRAC

If you provide designated services, you must enrol with AUSTRAC and provide details about your business, the services you offer and your key personnel. Enrolment is the entry point — but it's the start of your obligations, not the whole of them.

2. Assess your risk

Before you can manage money-laundering and terrorism-financing risk, you have to understand it. A risk assessment looks at your customers, the services you provide, how you deliver them and where, and rates the risk so your controls can be proportionate.

3. Build and maintain an AML/CTF program

Your program is the documented set of policies, procedures and controls that manage the risks you've identified. It must be approved by senior management, and your governing body is expected to oversee it and take reasonable steps to ensure you comply.

4. Appoint a compliance officer

You must appoint an AML/CTF compliance officer — the person responsible for your program day to day. Smaller businesses don't always have this seniority in-house, which is where a virtual AMLCO arrangement can help.

5. Know your customer (CDD)

Customer due diligence is how you establish who your customers are and the risk they bring, before and during your relationship with them. It includes verifying identity, understanding beneficial ownership where a customer is a company, and applying more scrutiny to higher-risk customers.

6. Monitor and report

The regime is ongoing. You monitor customers and transactions for changes in risk, and you report certain matters to AUSTRAC — including suspicious matters. Reporting obligations are a core part of being a reporting entity.

7. Keep records

You must make and keep accurate, complete records of your program and the steps you take to comply. For most obligations, records must be retained for seven years.

8. Train your people

Your program only works if your staff understand it. Training your team to recognise and handle risk is part of running a compliant business, not an optional extra.

Pulling it together

Each obligation feeds the next: your risk assessment shapes your program, your program drives your due diligence and monitoring, and your records prove you did the work. True Comply is built to run this as one connected system, so the evidence is there when you need it. If you'd like help mapping these obligations to your business, start the conversation.

Related insights

Compliance you can prove.

Tell us where you're at and we'll help you work out what applies to your business.

No jargon, no obligation.