Skip to main content
Rules Mate

Do banks and ADIs need to maintain a written AML/CTF program?

A computed answer from the Rules Mate applicability engine, with the exact condition, the outcome for every structure and size, and the primary source.

Short answer: Yes

Yes. This obligation applies to banks and ADIs whatever their structure or size. The deciding fact: Authorised deposit-taking institution — AML/CTF reporting entity.

The obligation in brief

Maintain a written AML/CTF program. Under the reformed AML/CTF Act (in force for existing reporting entities from 31 March 2026 and for Tranche 2 entities from 1 July 2026), a reporting entity's AML/CTF program is an ML/TF risk assessment plus AML/CTF policies that mitigate and manage those risks — this replaced the former Part A / Part B structure. The policies cover customer due diligence, ongoing CDD, transaction monitoring, reporting, record keeping, personnel due diligence and training, governance and senior manager approval, and the designation of an AML/CTF compliance officer.

Trigger: Becoming a reporting entity.

Why banks & adis get a different answer

Rules Mate runs its applicability engine across 9 business structures and 6 size bands for each of the 35 industries it maps. For 27 of those industries the answer for "Maintain a written AML/CTF program" is no. Banks & ADIs is one of the 8 where the answer is different: yes.

The deciding fact for banks and ADIs: Authorised deposit-taking institution — AML/CTF reporting entity.

About the industry: Authorised deposit-taking institutions regulated by APRA under the Banking Act 1959.

Compare a professional services (general) business with 6–19 employees structured as a Pty Ltd company: the obligation does not apply (Requires an AML/CTF designated service).

Answer by business structure and size

Each cell is the engine's outcome for a business in banks & adis with that structure and size, assuming it sells to consumers and small businesses and holds customer contact details. "Check" means the obligation turns on a fact the industry does not settle.

"Maintain a written AML/CTF program": outcome for banks and ADIs by structure and size
StructureNo employees1–5 employees6–19 employees20–99 employees100–499 employees500+ employees
Sole traderYesYesYesYesYesYes
PartnershipYesYesYesYesYesYes
TrustYesYesYesYesYesYes
Pty Ltd companyYesYesYesYesYesYes
Public companyYesYesYesYesYesYes
Not-for-profit (unregistered)YesYesYesYesYesYes
Registered charityYesYesYesYesYesYes
Super fundYesYesYesYesYesYes
Foreign companyYesYesYesYesYesYes

What the obligation requires

When due
Before providing the first designated service. Maintained on an ongoing basis, with independent evaluation at least once every 3 years.
Evidence to keep
ML/TF risk assessment, AML/CTF policies, governing body / senior manager approval records, compliance officer designation and AUSTRAC notification, training records, independent evaluation report.
Maximum penalty
Civil penalty of up to $36.4M (body corporate) or $7.28M (individual), maximum per contravention. Separate criminal offences also apply.
Regulator
AUSTRAC
Jurisdiction
Commonwealth (national)

Other obligations where banks & adis differ from the norm

Other industries with a non-default answer

Questions

Do banks and ADIs need to maintain a written AML/CTF program?
Yes. This obligation applies to banks and ADIs whatever their structure or size. The deciding fact: Authorised deposit-taking institution — AML/CTF reporting entity.
Is the answer the same for every industry?
No. For 27 of the 35 industries Rules Mate maps, the answer is no. Banks & ADIs is one of 8 industries with a different answer.

Related

Sources

Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.