
It isn't the review you may have heard about
Under the old regime, reporting entities had Part A of their program independently reviewed. The reforms replaced that with something broader: an independent evaluation of your entire AML/CTF program — risk assessment and policies together, in design and in practice.
The distinction matters. A review of Part A could be satisfied by someone reading your documentation and confirming it addressed the required elements. An evaluation asks a harder question: does this program actually work in this business? An evaluator who only reads your policies has not done the job.
For most newly captured firms this is a long way off. That is exactly why it is worth understanding now — because what the evaluator finds in 2029 is determined by what you do in 2026 and 2027.
When yours is actually due
Part 7 of the Transitional Rules 2026 staggers the first evaluation for newly regulated businesses, using the last two digits of your enrolment identifier — the number AUSTRAC assigned when you applied to enrol, which you'll know as your AUSTRAC account number:
- 30 June 2029 — if both of the last two digits are odd
- 31 December 2029 — if the second-last digit is odd and the last is even
- 30 June 2030 — if both of the last two digits are even
- 31 December 2030 — if the second-last digit is even and the last is odd
Strictly, these are deeming provisions rather than deadlines: conduct your first evaluation before the applicable date and you are taken to have met your policy's frequency requirement. The same staggering applies to certain virtual asset service providers and to financial advisers who previously provided only item 54 services.
If you were already enrolled on 30 March 2026 and have had at least one independent review of Part A under the pre-reform Rules, your first evaluation must be conducted before the later of four years after that review and 31 March 2027.
Go and look up your enrolment identifier today. It takes two minutes and it converts an abstract future obligation into a date you can put in a calendar and a program you can build backwards from.
How often after that
Your AML/CTF policies have to set the evaluation frequency themselves. Under section 26F(4)(f) of the Act, that frequency must be appropriate to the nature, size and complexity of your business — and at least once every three years.
Both limbs bite. Three years is a floor, not a default. If you write “every three years” into your policies, you should still be able to say why three years is right for a firm like yours. A small conveyancing practice with a stable local client base and a large agency writing offshore-funded developments do not sit in the same place, and a program that treats the statutory minimum as the automatic answer is one of the first things an evaluator will notice.
Who is allowed to do it
The Act doesn't define independence, but AUSTRAC's guidance is clear about what it expects. The evaluator should be independent of the areas being evaluated, able to exercise independent judgement, and not responsible for implementing or maintaining the program. In practice that rules out two people most firms would reach for first:
- Your compliance officer, or anyone on the compliance team. They run the program. They cannot evaluate it.
- Whoever wrote the program — including whoever assessed your ML/TF risks. Someone assessing their own work is not an evaluation.
Independent does not mean external. AUSTRAC expressly allows an internal evaluator — internal audit, for instance — provided that function is genuinely separated from compliance. Most newly regulated firms are nowhere near that size, so external is the realistic answer: a consultant, an audit firm, or a specialist AML practice.
What matters is that you can explain the independence, not that you paid someone. Document why the person you chose was appropriately independent and competent, and keep that reasoning with the report.
What the evaluator will ask you for
The evaluation covers the program end to end. Expect requests along these lines:
- Your ML/TF risk assessment, and the working that produced the ratings — not just the conclusions
- Your AML/CTF policies, with evidence they were approved by a senior manager and when
- A sample of customer files, to test whether the CDD you describe is the CDD you actually performed
- Your beneficial ownership records for company and trust clients, including where the trail was hard
- Screening records — sanctions, PEP and adverse media — and what you did with the hits
- Your reporting history, and evidence of how suspicious matters were escalated and decided
- Training records: who, when, on what
- Board or senior management papers showing the program was overseen, not just filed
Read that list again and note how much of it is evidence rather than documentation. A firm that captured its work as it went can assemble this in an afternoon. A firm that has a beautiful policy binder and nothing behind it is looking at weeks of reconstruction, and reconstruction is visible.
The findings that keep recurring
Across regimes and jurisdictions, the same handful of findings dominate evaluation reports.
The generic risk assessment: a document that could describe any firm in the sector, with controls that cannot be traced to any identified risk.
Policies that describe a different business: the program says clients are verified before the engagement begins; the files show verification happening after settlement, or not at all.
Decisions without reasoning: a screening hit was cleared, a client was rated low risk, a matter was not reported — and there is no record of why. The decision may have been perfectly sound. Without the reasoning, nobody can tell.
Ongoing due diligence that stopped: clients onboarded properly in year one and never looked at again.
Training as a single event: everyone was trained at go-live, nobody since, and half the people doing CDD today were not there.
The compliance officer on paper: someone was appointed and notified to AUSTRAC, but no time was allocated, no reporting line exists, and no decisions trace back to them.
None of these are exotic. All of them are avoidable by a firm that treats the program as something it runs rather than something it owns.
What you do with the report
Your AML/CTF policies must require the written report to be delivered to your governing body, and to any senior manager responsible for approving your risk assessment and policies under section 26P. That is the point of the exercise — it puts an independent view of your risk management in front of the people accountable for it.
Then it needs to do something. Findings should turn into a remediation plan with owners and dates, tracked to closure, with the closure evidenced. An adverse finding about your risk assessment is itself a trigger to review that assessment, and AUSTRAC expects that review to happen as soon as practicable after your governing body receives the report.
The worst outcome is not a critical report. It is a critical report that sits in a folder until the next evaluation notices nothing changed.
The three years before it are the point
An independent evaluation does not test what you can produce in the month before it starts. It tests the record your business left behind while it was working.
Firms that capture evidence as they go — the check, the decision, the reasoning, the date, the person — walk into an evaluation with the answer already assembled. Firms that plan to get ready for it later discover that “later” means recreating three years of judgement calls from memory, which is both expensive and unconvincing.
Build the evidence trail now and the evaluation becomes an administrative exercise rather than an event.
True Comply builds programs that produce their own evidence, and works with firms preparing for an independent evaluation — before it becomes urgent.
Related insights
- Have you already hit 'set and forget' on your AML program?
Getting compliant · 5 min read
- Compliance you can prove: why evidence beats a policy binder
Technology · 4 min read
- Writing your first AML/CTF risk assessment
How to · 5 min read