If AUSTRAC asked for your AML/CTF program tomorrow, would it reflect how your firm actually works?
Upload your ML/TF risk assessment or AML/CTF policies, or one of five other compliance documents. In about three minutes you receive a gap score and your three highest-priority gaps, each linked to the requirement it relates to.
AML/CTF Tranche 2 · in force since 1 July 2026[2]
On 28 August 2026 AUSTRAC began issuing section 167 notices to real estate agents, accountants, lawyers and jewellers that appear to be providing designated services without enrolling.[3] Enrolment is the first step. The program behind it is what AUSTRAC expects you to document, approve and follow.[4],[1]
Civil penalties under the AML/CTF Act are up to $36.4M per contravention for a body corporate and up to $7.28M for other persons.[1] Those are maximums set by the court, not typical outcomes. For FY26/27, AUSTRAC has said it expects “effort, not perfection”, and will act early against businesses that fail to enrol.[4]
One free document. Verified email required. Personal information is scrubbed before analysis and your file is deleted within 24 hours.
Independent service. Not affiliated with or endorsed by AUSTRAC. General information, not legal advice.
Upload your program
Your ML/TF risk assessment and AML/CTF policies, as a text-based PDF or Word file.
Personal information removed
Names, contact details and identifiers are scrubbed before analysis. The file is deleted within 24 hours.
Gap score and top three gaps
Scored by fixed rules against the reformed requirements, each gap cited to its source.
What we check
30 requirements and 173 individual checks across seven areas, drawn from the AML/CTF Act, the AML/CTF Rules and AUSTRAC guidance. Each element is marked as required by law or recommended by guidance, and requirements that do not apply to your sector are left out.
Governance
4 requirements · 28 checks
Senior manager approval, governance and oversight, your AML/CTF compliance officer, and how the program is documented.
Risk assessment
2 requirements · 15 checks
Your ML/TF risk assessment by customer, service, delivery channel and jurisdiction, and customer risk ratings.
Policies and review
2 requirements · 14 checks
AML/CTF policies built on the risk assessment, and when and how you review them.
Customer due diligence
10 requirements · 56 checks
Customer identification and verification, beneficial owners, politically exposed persons, sanctions screening, enhanced and ongoing due diligence, and transaction monitoring.
Reporting
6 requirements · 25 checks
Suspicious matter reports, threshold transaction reports, tipping-off controls and annual compliance reporting.
Personnel
2 requirements · 14 checks
Personnel due diligence and AML/CTF training.
Assurance, records and enrolment
4 requirements · 21 checks
Independent evaluation, record keeping and AUSTRAC enrolment.
Built your program from an AUSTRAC starter kit? The kits are written for businesses with particular characteristics, and AUSTRAC expects you to consider whether yours matches.[6],[4] The check shows where your program still reads like the template.
Other documents we check
The same engine scores five more document types. Each check is drawn from the legislation and the regulator's own guidance, marks every element as required by law or recommended by guidance, and links each finding to its source.
Privacy policy
9 requirements · 9 checks
Checked against APP 1.3 and 1.4 and the OAIC APP guidelines.
- Not having a privacy policy that meets APP 1.3 and 1.4 can attract a civil penalty of up to 200 penalty units ($72,800) per contravention. Privacy Act 1988 s13K
Whistleblower policy
9 requirements · 20 checks
Checked against the six matters in Corporations Act s1317AI(5) and ASIC RG 270 good practice.
- Public companies, large proprietary companies and proprietary companies that are trustees of registrable superannuation entities must have a whistleblower policy that sets out the matters in s1317AI(5) and make it available to officers and employees. Corporations Act 2001 s1317AI(1)-(3)
- Not having and making available a whistleblower policy is a strict liability offence with a maximum of 60 penalty units ($21,840). Corporations Act 2001 s1317AI(4) and Schedule 3
Data breach response plan
8 requirements · 14 checks
Checked against the Notifiable Data Breaches provisions (Privacy Act Part IIIC) and the OAIC's response plan guidance.
- An entity that suspects an eligible data breach must take all reasonable steps to complete its assessment within 30 days after becoming aware of the grounds for suspicion. Privacy Act 1988 s26WH(2)
- The OAIC says all entities should have a data breach response plan, in writing, regularly reviewed and tested. OAIC, Part 2: preparing a data breach response plan
Collection notice (APP 5)
10 requirements · 10 checks
Checked against the ten matters in APP 5.2 and the OAIC APP 5 guidelines.
- At or before collection, or as soon as practicable afterwards, an APP entity must take reasonable steps to notify individuals of the APP 5.2 matters, or ensure they are aware of them. Privacy Act 1988 Sch 1, APP 5.1-5.2
Psychosocial risk register
7 requirements · 14 checks
Checked against the model WHS Regulations (r34-38 and r55A-55D), the WHS Act consultation duty and the model Code of Practice.
- A person conducting a business or undertaking must manage psychosocial risks under the risk management process in Part 3.1 and, in choosing controls, have regard to matters including the duration, frequency and severity of exposure, how hazards interact, the design of work and workplace interactions. Work Health and Safety Regulations r55C-55D (model provisions)
- In Victoria, the Occupational Health and Safety (Psychological Health) Regulations 2025 have commenced under the OHS Act 2004, which applies there instead of the model WHS laws. WorkSafe Victoria, psychological health
Check your document
One free scored check per verified email. Documents that cannot be scored do not use it.
We identify the document type before scoring it.
Optional. Decides whether a whistleblower policy is legally required for you (Corporations Act s1317AI).
Sector decides which AML/CTF requirements apply, for example legal professional privilege for law practices.
Drag your document here
Text-based PDF or Word (.docx), up to 4 MB. Scanned documents are not accepted on the free check.
Before you upload
Select your sector to continue.
General information, not legal advice. Not an independent evaluation under the AML/CTF Act. Not affiliated with AUSTRAC.
Questions
Is this an independent evaluation of my AML/CTF program?
No. The AML/CTF Act requires an independent evaluation of your whole program at least once every three years, by an evaluator who did not develop it and who also tests whether your policies are followed in practice. This check reads your document only. It is a self-assessment tool that helps you find and prioritise gaps before your evaluation.
Do I need an auditor?
For most Tranche 2 businesses the AML/CTF Act does not require an external auditor. It requires an independent evaluation at least every three years, which can be internal if the evaluator is independent. An external auditor is required if AUSTRAC issues a written notice. Other regimes, such as state trust-account rules, can require their own audits. Your results page explains which apply.
Which documents can I check?
AML/CTF programs, privacy policies, APP 5 collection notices, data breach response plans, whistleblower policies and psychosocial risk registers. Choose the type when you upload, or let us detect it. If a document looks like a different type from the one you chose, we ask before scoring it, and a document we cannot score does not use your free check.
What happens to my document?
We extract the text, automatically remove personal information such as names, contact details, addresses, dates of birth, government identifiers and bank details, and send the scrubbed text to overseas AI processing providers (including in the United States) to produce your results. Automated scrubbing can miss unusual formats. Your uploaded file is deleted within 24 hours; the findings stay in your account until you delete them.
Which files can I upload?
A text-based PDF or Word document (.docx) up to 4 MB. The free check does not accept scanned documents, because we do not send page images to any processing provider. Paid plans can run text recognition on your own device, so page images never leave it.
What does the score mean?
It measures how fully your document addresses published requirements, weighted towards core requirements and towards elements the law requires. It is calculated by fixed rules from what we could verify in your document. It is not a finding that your business complies or does not comply with the AML/CTF Act.
Is it really free?
Yes. One scored check per verified email, with no card required. If a document cannot be scored, for example because it is a different type of document or a scan, it does not use your free check. Paid plans add the full report and the evidence pack.
Is Rules Mate affiliated with AUSTRAC?
No. Rules Mate is an independent service and is not affiliated with or endorsed by AUSTRAC. AUSTRAC does not endorse any AML/CTF program or provider. We cite AUSTRAC's published requirements so you can check every finding yourself.
Independent evaluation requirements:[5] AUSTRAC does not endorse any AML/CTF program or provider, including ours.[7]
Sources
- AUSTRAC: consequences of not complying (civil penalties and infringement notices)
- AUSTRAC: changes to AML/CTF obligations, what you need to do
- AUSTRAC: AUSTRAC issues notices to non-enrolled businesses (28 August 2026)
- AUSTRAC: updated regulator statement of expectations (May 2026)
- AUSTRAC: Step 5, conduct an independent evaluation
- AUSTRAC: program starter kits
- AUSTRAC: consultants and compliance
Verified 3 October 2026. General information, not legal advice. Not an independent evaluation under the AML/CTF Act. Not affiliated with AUSTRAC. Rules Mate is an independent service and is not affiliated with or endorsed by AUSTRAC.