If AUSTRAC asked for your AML/CTF program tomorrow, would it reflect how your firm actually works?
Upload your ML/TF risk assessment or AML/CTF policies, or one of five other compliance documents. In about three minutes you receive a gap score and your three highest-priority gaps, each linked to the requirement it relates to.
AML/CTF Tranche 2 · in force since 1 July 2026[2]
On 28 August 2026 AUSTRAC began issuing section 167 notices to real estate agents, accountants, lawyers and jewellers that appear to be providing designated services without enrolling.[3] Enrolment is the first step. The program behind it is what AUSTRAC expects you to document, approve and follow.[4],[1]
Civil penalties under the AML/CTF Act are up to $36.4M per contravention for a body corporate and up to $7.28M for other persons.[1] Those are maximums set by the court, not typical outcomes. For FY26/27, AUSTRAC has said it expects “effort, not perfection”, and will act early against businesses that fail to enrol.[4]
One free document. Verified email required. Personal information is scrubbed before analysis and your file is deleted within 24 hours.
Independent service. Not affiliated with or endorsed by AUSTRAC. General information, not legal advice.
Upload your program
Your ML/TF risk assessment and AML/CTF policies, as a text-based PDF or Word file.
Personal information removed
Names, contact details and identifiers are scrubbed before analysis. The file is deleted within 24 hours.
Gap score and top three gaps
Scored by fixed rules against the reformed requirements, each gap cited to its source.
What we check
30 requirements and 173 individual checks across seven areas, drawn from the AML/CTF Act, the AML/CTF Rules and AUSTRAC guidance. Each element is marked as required by law or recommended by guidance, and requirements that do not apply to your sector are left out.
Governance
4 requirements · 28 checks
Senior manager approval, governance and oversight, your AML/CTF compliance officer, and how the program is documented.
Risk assessment
2 requirements · 15 checks
Your ML/TF risk assessment by customer, service, delivery channel and jurisdiction, and customer risk ratings.
Policies and review
2 requirements · 14 checks
AML/CTF policies built on the risk assessment, and when and how you review them.
Customer due diligence
10 requirements · 56 checks
Customer identification and verification, beneficial owners, politically exposed persons, sanctions screening, enhanced and ongoing due diligence, and transaction monitoring.
Reporting
6 requirements · 25 checks
Suspicious matter reports, threshold transaction reports, tipping-off controls and annual compliance reporting.
Personnel
2 requirements · 14 checks
Personnel due diligence and AML/CTF training.
Assurance, records and enrolment
4 requirements · 21 checks
Independent evaluation, record keeping and AUSTRAC enrolment.
Built your program from an AUSTRAC starter kit? The kits are written for businesses with particular characteristics, and AUSTRAC expects you to consider whether yours matches.[6],[4] The check shows where your program still reads like the template.
Other documents we check
The same engine scores five more document types. Each check is drawn from the legislation and the regulator's own guidance, marks every element as required by law or recommended by guidance, and links each finding to its source.
Privacy policy
9 requirements · 9 checks
Checked against APP 1.3 and 1.4 and the OAIC APP guidelines.
- Not having a privacy policy that meets APP 1.3 and 1.4 can attract a civil penalty of up to 200 penalty units ($72,800) per contravention. Privacy Act 1988 s13K
Whistleblower policy
9 requirements · 20 checks
Checked against the six matters in Corporations Act s1317AI(5) and ASIC RG 270 good practice.
- Public companies, large proprietary companies and proprietary companies that are trustees of registrable superannuation entities must have a whistleblower policy that sets out the matters in s1317AI(5) and make it available to officers and employees. Corporations Act 2001 s1317AI(1)-(3)
- Not having and making available a whistleblower policy is a strict liability offence with a maximum of 60 penalty units ($21,840). Corporations Act 2001 s1317AI(4) and Schedule 3
Data breach response plan
8 requirements · 14 checks
Checked against the Notifiable Data Breaches provisions (Privacy Act Part IIIC) and the OAIC's response plan guidance.
- An entity that suspects an eligible data breach must take all reasonable steps to complete its assessment within 30 days after becoming aware of the grounds for suspicion. Privacy Act 1988 s26WH(2)
- The OAIC says all entities should have a data breach response plan, in writing, regularly reviewed and tested. OAIC, Part 2: preparing a data breach response plan
Collection notice (APP 5)
10 requirements · 10 checks
Checked against the ten matters in APP 5.2 and the OAIC APP 5 guidelines.
- At or before collection, or as soon as practicable afterwards, an APP entity must take reasonable steps to notify individuals of the APP 5.2 matters, or ensure they are aware of them. Privacy Act 1988 Sch 1, APP 5.1-5.2
Psychosocial risk register
7 requirements · 14 checks
Checked against the model WHS Regulations (r34-38 and r55A-55D), the WHS Act consultation duty and the model Code of Practice.
- A person conducting a business or undertaking must manage psychosocial risks under the risk management process in Part 3.1 and, in choosing controls, have regard to matters including the duration, frequency and severity of exposure, how hazards interact, the design of work and workplace interactions. Work Health and Safety Regulations r55C-55D (model provisions)
- In Victoria, the Occupational Health and Safety (Psychological Health) Regulations 2025 have commenced under the OHS Act 2004, which applies there instead of the model WHS laws. WorkSafe Victoria, psychological health
Safe work method statement (SWMS)
10 requirements · 21 checks
Checked against the model WHS Regulations r299-r303 and Safe Work Australia's SWMS information sheet.
- Before high risk construction work starts, the person conducting the business or undertaking must ensure a safe work method statement is prepared that identifies the high risk construction work, specifies its hazards and risks, describes the control measures, and describes how they will be implemented, monitored and reviewed. Work Health and Safety Regulations r299 (model provisions)
- If high risk construction work is not carried out in accordance with the safe work method statement, it must be stopped immediately or as soon as it is safe to do so, and resumed only in accordance with the statement. Work Health and Safety Regulations r300 (model provisions)
Modern slavery statement
9 requirements · 17 checks
Checked against the seven mandatory criteria in Modern Slavery Act 2018 s16 and the approval and signature rules in s13 and s14.
- An entity with consolidated revenue of at least $100 million that is an Australian entity or carries on business in Australia must give the Minister a modern slavery statement for each reporting period, within 6 months after the period ends. Modern Slavery Act 2018 (Cth) ss5, 13
- A modern slavery statement must address the seven mandatory criteria in s16(1)(a)-(g) and include details of its approval by the principal governing body. Modern Slavery Act 2018 (Cth) s16
Complaints / IDR procedure (RG 271)
11 requirements · 21 checks
Checked against the enforceable paragraphs of ASIC RG 271, Corporations Act s912A(1)(g) and NCCP Act s47(1)(h).
- An AFS licensee that provides financial services to retail clients, and every credit licensee, must have an internal dispute resolution procedure that meets the standards and requirements made or approved by ASIC, and must be a member of AFCA. Corporations Act 2001 s912A(1)(g), (2); NCCP Act s47(1)(h)-(i)
- For a standard complaint, the IDR response must be given no later than 30 calendar days after the complaint is received; other maximum timeframes apply to superannuation, traditional trustee and some credit complaints. ASIC RG 271.56 and Table 2 (enforceable)
ISO/IEC 27001 Statement of Applicability
6 requirements · 9 checks
Checked against ISO/IEC 27001:2022 clause 6.1.3(d), referring to clause and Annex A control numbers only.
- ISO/IEC 27001 asks an organisation to produce a Statement of Applicability that lists the controls it needs, why each is included, whether each is implemented, and why any Annex A control is excluded. ISO/IEC 27001:2022 cl. 6.1.3(d) (reference only)
- ISO/IEC 27001 is a voluntary standard: certification is usually required by a customer, contract or tender rather than by statute. ISO/IEC 27001 (voluntary standard)
Incident management system (NDIS or aged care)
10 requirements · 22 checks
Checked against the NDIS incident management rules (ss9-24) and the Aged Care Act 2024 and Aged Care Rules 2025 incident and SIRS requirements.
- NDIS providers must notify the Commissioner of a death, serious injury, abuse or neglect, unlawful sexual or physical contact or assault, or sexual misconduct within 24 hours of key personnel becoming aware, with further details within 5 business days; other reportable incidents are notified within 5 business days. NDIS (Incident Management and Reportable Incidents) Rules 2018 ss20-21
- Aged care providers must notify Priority 1 reportable incidents within 24 hours of becoming aware of them and Priority 2 reportable incidents within 30 days. Aged Care Rules 2025 ss165A-25, 165A-30
Critical infrastructure risk management program (SOCI)
11 requirements · 24 checks
Checked against Part 2A of the SOCI Act (ss30AC-30AH) and the CIRMP Rules (LIN 23/006) ss6-11.
- A responsible entity must adopt and maintain a critical infrastructure risk management program, comply with it, review it regularly and keep it up to date; each duty carries a civil penalty of up to 200 penalty units ($72,800). Security of Critical Infrastructure Act 2018 ss30AC-30AF
- Within 90 days after the end of each financial year the responsible entity must give the regulator a report on its program in the approved form, approved by its board, council or other governing body if it has one. Security of Critical Infrastructure Act 2018 s30AG
Direct marketing consent procedure
10 requirements · 18 checks
Checked against the Spam Act 2003 (ss16-18 and Schedule 2), the Do Not Call Register Act 2006 and APP 7.
- A commercial electronic message with an Australian link must not be sent without the recipient's express or inferred consent, and a business relying on consent bears the evidential burden of showing it had consent (s16(5)). Spam Act 2003 s16 and Schedule 2
- Every commercial electronic message must include a functional unsubscribe facility that works for at least 30 days after the message is sent, and an unsubscribe request takes effect within 5 business days. Spam Act 2003 s18 and Schedule 2 cl 6
Cyber incident response plan
11 requirements · 18 checks
Checked against ASD's incident response planning guidance and, for APRA-regulated entities, CPS 234 paras 23-26 and 35-36.
- A business with annual turnover over $3 million, or a SOCI Part 2B responsible entity, that makes a ransomware or cyber extortion payment must report it within 72 hours, with a civil penalty of up to 60 penalty units ($21,840) for not reporting. Cyber Security Act 2024 s27; Cyber Security (Ransomware Payment Reporting) Rules 2025 s6
- APRA-regulated entities must notify APRA as soon as possible and no later than 72 hours after becoming aware of a material information security incident, and within 10 business days of a material control weakness they cannot remediate in time. APRA Prudential Standard CPS 234 paras 35-36
Check your document
One free scored check per verified email. Documents that cannot be scored do not use it.
We identify the document type before scoring it.
Optional. Decides whether a whistleblower policy is legally required for you (Corporations Act s1317AI).
Sector decides which AML/CTF requirements apply, for example legal professional privilege for law practices.
Drag your document here
Text-based PDF or Word (.docx), up to 4 MB. Scanned documents are not accepted on the free check.
Before you upload
Select your sector to continue.
General information, not legal advice. Not an independent evaluation under the AML/CTF Act. Not affiliated with AUSTRAC.
Questions
Is this an independent evaluation of my AML/CTF program?
No. The AML/CTF Act requires an independent evaluation of your whole program at least once every three years, by an evaluator who did not develop it and who also tests whether your policies are followed in practice. This check reads your document only. It is a self-assessment tool that helps you find and prioritise gaps before your evaluation.
Do I need an auditor?
For most Tranche 2 businesses the AML/CTF Act does not require an external auditor. It requires an independent evaluation at least every three years, which can be internal if the evaluator is independent. An external auditor is required if AUSTRAC issues a written notice. Other regimes, such as state trust-account rules, can require their own audits. Your results page explains which apply.
Which documents can I check?
AML/CTF programs, privacy policies, APP 5 collection notices, data breach response plans, whistleblower policies, psychosocial risk registers, safe work method statements (SWMS), modern slavery statements, complaints (IDR) procedures and ISO/IEC 27001 Statements of Applicability. Choose the type when you upload, or let us detect it. If a document looks like a different type from the one you chose, we ask before scoring it, and a document we cannot score does not use your free check.
What happens to my document?
We read your file in memory on our application servers, extract the text and automatically remove personal information such as names, contact details, addresses, dates of birth, government identifiers and bank details. Only the scrubbed text is sent to our AI providers to produce your results. AI processing takes place outside Australia. Our AI providers do not use the content we send them to train their models, under the commercial terms we use. Our AI providers may keep that content for up to 30 days to operate their services and monitor for misuse, and longer only where it is flagged for a breach of their usage policies or where the law requires it. Automated scrubbing can miss unusual formats. We do not store your uploaded file. The findings are kept in our database in Australia until you delete them.
Which files can I upload?
A text-based PDF or Word document (.docx) up to 4 MB. The free check does not accept scanned documents, because we do not send page images to any processing provider. Paid plans can run text recognition on your own device, so page images never leave it.
What does the score mean?
It measures how fully your document addresses published requirements, weighted towards core requirements and towards elements the law requires. It is calculated by fixed rules from what we could verify in your document. It is not a finding that your business complies or does not comply with the AML/CTF Act.
Is it really free?
Yes. One scored check per verified email, with no card required. If a document cannot be scored, for example because it is a different type of document or a scan, it does not use your free check. Paid plans add the full report and the evidence pack.
Is Rules Mate affiliated with AUSTRAC?
No. Rules Mate is an independent service and is not affiliated with or endorsed by AUSTRAC. AUSTRAC does not endorse any AML/CTF program or provider. We cite AUSTRAC's published requirements so you can check every finding yourself.
Independent evaluation requirements:[5] AUSTRAC does not endorse any AML/CTF program or provider, including ours.[7]
Sources
- AUSTRAC: consequences of not complying (civil penalties and infringement notices)
- AUSTRAC: changes to AML/CTF obligations, what you need to do
- AUSTRAC: AUSTRAC issues notices to non-enrolled businesses (28 August 2026)
- AUSTRAC: updated regulator statement of expectations (May 2026)
- AUSTRAC: Step 5, conduct an independent evaluation
- AUSTRAC: program starter kits
- AUSTRAC: consultants and compliance
Verified 3 October 2026. General information, not legal advice. Not an independent evaluation under the AML/CTF Act. Not affiliated with AUSTRAC. Rules Mate is an independent service and is not affiliated with or endorsed by AUSTRAC.