Independent review of AML/CTF program
Reporting entities must have their whole AML/CTF program independently evaluated at least once every 3 years.
Who must comply
All AUSTRAC reporting entities.
What triggers it
Having an AML/CTF program in place.
When due
At least once every 3 years, at the frequency set in your AML/CTF policies. Newly regulated entities: first evaluation due 30 June 2029 – 31 December 2030 depending on AUSTRAC account number.
Evidence required
Independent evaluation scope, evaluator independence record, evaluation report, governing body response, remediation tracker.
Max penalty
Civil penalty of up to $36.4M (body corporate) or $7.28M (individual), maximum per contravention, under the general AML/CTF Act civil penalty regime
Who must comply with this? The applicability test by industry, business structure and size.
Summary
Under the reformed AML/CTF Act, the former independent review of a Part A program has been replaced by an independent evaluation of the whole AML/CTF program (ML/TF risk assessment and AML/CTF policies). It must happen at least once every 3 years, at a frequency set in your AML/CTF policies. The evaluator can be internal or external but must be independent — for example, not involved in developing the program — and there are no mandatory qualifications. The evaluation tests whether you appropriately identified, assessed, mitigated and managed your ML/TF risks and complied with your policies. For newly regulated Tranche 2 entities, the first evaluation is due between 30 June 2029 and 31 December 2030, depending on the last two digits of the AUSTRAC account number. Separately, AUSTRAC can require an external audit by written notice.
Enforced by
Source legislation
Topics
Related
- CWLTHSuspicious matter, threshold, and IFTI reporting to AUSTRACLodge SMRs, TTRs ($10K+ cash), and IFTI reports via AUSTRAC Online.
- CWLTHEnrol with AUSTRAC as a reporting entityTranche 2 entities must enrol with AUSTRAC within 28 days of first providing a designated service (29 July 2026 for services from 1 July 2026).
- CWLTHDesignate an AML/CTF Compliance OfficerReporting entities must designate an eligible AML/CTF compliance officer at management level and notify AUSTRAC.
- CWLTHDetect + enhance due diligence on Domestic + Foreign PEPsAML/CTF Rules require detection + EDD on Politically Exposed Persons (foreign + domestic + international organisation).
- CWLTHMaintain a written AML/CTF programEvery reporting entity needs a documented AML/CTF program — an ML/TF risk assessment plus AML/CTF policies.
- CWLTHCustomer due diligence (KYC) on every customerIdentify and verify every customer (and beneficial owner) before providing a designated service.
Reading
Frequently asked questions
- Who must comply with Independent review of AML/CTF program?
- All AUSTRAC reporting entities.
- What triggers Independent review of AML/CTF program?
- Having an AML/CTF program in place.
- When is Independent review of AML/CTF program due?
- At least once every 3 years, at the frequency set in your AML/CTF policies. Newly regulated entities: first evaluation due 30 June 2029 – 31 December 2030 depending on AUSTRAC account number.
- What is the maximum penalty for Independent review of AML/CTF program?
- Civil penalty of up to $36.4M (body corporate) or $7.28M (individual), maximum per contravention, under the general AML/CTF Act civil penalty regime
- What evidence is required for Independent review of AML/CTF program?
- Independent evaluation scope, evaluator independence record, evaluation report, governing body response, remediation tracker.
Source: https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/your-amlctf-program/develop-your-amlctf-programs/step-5-conduct-independent-evaluation. Rules Mate is not a law firm. Always verify against the live regulator source before acting.