Getting compliant

Have you already hit 'set and forget' on your AML program?

True Comply · · 5 min read

← Back to Insights
Low light catching a thin layer of dust along the spine of a ring binder on an office shelf.

The June rush, and then nothing

A lot of firms did the hard part. They worked out they were captured, enrolled before the deadline, appointed a compliance officer, wrote a risk assessment and a set of policies, got them approved by a senior manager, and put the whole thing in a folder.

Then July became August, the deals kept coming, and nobody opened the folder again.

This is the most common failure mode in the regime, and it is not a failure of intent. It happens because building the program felt like a project with an end date, and nothing in the day-to-day pushes back when it goes quiet. There is no alarm. The program simply drifts out of alignment with the business while everyone assumes it is fine.

The obligation is 'develop, maintain and comply'

It is worth being precise about what the law asks for, because the wording does the work. You must develop, maintain and comply with an AML/CTF program. Three verbs, and most firms have only done the first.

Concretely, that means you have to review and update your program so it remains current as your circumstances change, keep an up-to-date ML/TF risk assessment, get senior manager approval for the updates, actually follow your own policies in daily operations, and monitor whether those policies are working. Your policies themselves have to be reviewed at least once every three years, and so does your risk assessment.

A program that was accurate on 1 July 2026 and untouched since is not a compliant program that happens to be old. It is a program that has stopped describing the business it governs.

What should have triggered a review by now

Section 26D sets a floor of reviewing your risk assessment at least once every three years. But it also lists triggers that don't wait for the calendar, and two of them matter here.

The first is a significant change to the factors your risk assessment is built on. In a professional services firm, that usually looks like something quite ordinary:

  • You took on a new type of client — first offshore buyer, first discretionary trust, first client introduced by a referrer you don't know well
  • You started a new service line, or wound one back
  • You changed how you deliver: more remote onboarding, work coming through a portal or an intermediary, a new office in a new market
  • You acquired a rent roll, a client book or another practice, and inherited files you never assessed
  • Your people changed — the person doing most of your CDD left, or a team of new staff joined
  • You changed systems, or the platform you rely on changed what it does

The second is AUSTRAC communicating risk information to you. This is a separate trigger in its own right, not a variety of the first. If AUSTRAC gives you information identifying or assessing risks connected to the designated services you provide, that obliges a review — whether or not anything about your business has changed.

An adverse finding about your risk assessment in an independent evaluation report is a further trigger, and one you'll meet later in the cycle.

If any of the above happened since July and your risk assessment still has one date on it, the review is overdue.

Ongoing due diligence is where it shows first

Initial CDD tends to survive, because it sits in the path of getting a job started. Ongoing due diligence is the part that quietly stops, because nothing in the workflow demands it.

But client risk moves. A director changes. Ownership restructures. A name appears on a sanctions list or in adverse media. A long-standing client starts behaving in a way that doesn't match what you know about them. If the only time you looked was at onboarding, you will not know, and “we checked them in 2026” is not an answer to a question about 2028.

This is the practical case for monitoring that runs continuously rather than in an annual sweep — not because a sweep is worthless, but because the gap between two sweeps is where the exposure sits.

Six questions to test whether yours is alive

Answer honestly. If more than one or two land badly, the program has stopped moving.

  • When was your risk assessment last reviewed — and is there a record of the review, or only of the original?
  • Does it reflect the clients you actually took on in the last six months, including the awkward ones?
  • Can your compliance officer point to a decision they made in the last quarter, and the reasoning behind it?
  • Has anyone been trained since go-live — particularly anyone who joined afterwards?
  • Are your existing clients under any form of ongoing monitoring, or was the check a one-off at onboarding?
  • Has your senior management or governing body seen anything about how the program is performing since they approved it?

The last one is the question firms most often miss and the one an evaluator will look for first. Oversight that produced a single approval and then nothing is difficult to describe as oversight.

What a living program looks like

It is less work than it sounds, and it is mostly rhythm rather than effort.

A living program has a review log — dates, what was looked at, what changed, who approved it — so the document has a history instead of a birthday. It has a standing item at whatever passes for your management meeting, even if the item is often “no change”. It has training with a schedule and an induction step for new starters. It has monitoring that runs without anyone remembering to start it. And it captures the reasoning behind decisions at the moment they're made, because reconstructing judgement calls two years later is both painful and unconvincing.

The pay-off is not abstract. Every one of those habits produces the evidence you will need the first time somebody — an evaluator, an auditor, AUSTRAC, a bank doing due diligence on you — asks you to show your work.

The quiet version of the risk

There is a version of this where nothing goes wrong: the program is stale, the clients are fine, nobody ever asks.

The other version is that a file goes bad, and the question becomes what your program said should have happened and whether it did. A program that has been maintained gives you a defensible answer. A program frozen at go-live gives you a document that describes a business you no longer are.

Neither outcome is knowable in advance. That is the whole reason maintenance is the obligation.

True Comply keeps programs current rather than handing you a document and walking away — with monitoring that runs on its own and an evidence trail that builds as you work.

Related insights

Compliance you can prove.

Tell us where you're at and we'll help you work out what applies to your business.

No jargon, no obligation.