Services

AML Policy and Procedures Australia

Having an AML/CTF policy and procedures in place is a core legal requirement for every reporting entity in Australia. Your documentation must be tailored to your business, practical for your team to follow and kept current as your risks and obligations evolve. At One AML, we develop AML policies and procedures that meet AUSTRAC requirements and actually work in practice, not documents that sit in a drawer and collect dust.

Illustration showing a checklist with blue check marks connected by an arrow to two documents labeled 'AML/CTF Compliance Program' and 'AML/CTF Risk Assessment' on a dark background with a purple circle.

We’re proud to assist small to enterprise-scale businesses across all industry sectors.

What Are AML Policies and Procedures?

AML policies and procedures are the written documentation that sets out how your business identifies, manages and responds to money laundering and terrorism financing risks. They translate your AML/CTF risk assessment into day-to-day operational rules that your staff can understand and apply.

Under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, every reporting entity must have documented policies and procedures as part of their AML/CTF program. These documents form the operational backbone of your compliance framework.

Your AML policies and procedures must cover:

  • How your business identifies and assesses ML/TF risk
  • Your customer due diligence and Know Your Customer processes
  • How you onboard new customers and verify their identity
  • Beneficial ownership identification and verification
  • Politically Exposed Person (PEP) and sanctions screening
  • Ongoing monitoring of customer relationships and transactions
  • How suspicious activity is identified, escalated and reported
  • Your Suspicious Matter Reporting process
  • Record-keeping obligations and how records are maintained
  • Staff training requirements and how compliance is monitored internally
  • The role and responsibilities of your AML/CTF Compliance Officer
  • How and when your program and documentation are reviewed and updated

Why Generic Templates Are Not Enough

AUSTRAC expects your AML policies and procedures to reflect your actual business. A document that does not account for your specific customer types, services, delivery channels and risk profile will not satisfy your obligations and will not help your staff manage compliance in practice.

Generic templates downloaded from the internet or purchased off the shelf present several problems:

  • They are not tailored to your risk assessment findings
  • They may reference obligations, thresholds or processes that do not apply to your business
  • They may omit risks or obligations that are specific to your industry
  • They give your staff no meaningful guidance on how to actually apply the rules
  • They are unlikely to hold up under an AUSTRAC review or independent audit

A properly developed set of AML policies and procedures is specific to your business, written in plain language your team can follow and directly connected to your risk assessment. That is what One AML delivers.

Who Needs AML Policies and Procedures in Australia?

Every reporting entity under the AML/CTF Act must have documented AML policies and procedures as part of their AML/CTF program. This applies to both existing reporting entities and businesses newly captured under the Tranche 2 reforms from 1 July 2026.

Businesses that must have AML policies and procedures in place include:

  • Banks, credit unions and other deposit-taking institutions
  • Remittance dealers and money transfer businesses
  • Digital currency exchange providers
  • Financial planners and advisers
  • Mortgage brokers
  • Lawyers and law firms providing certain services (from 1 July 2026)
  • Accountants and bookkeepers providing certain services (from 1 July 2026)
  • Real estate agents and agencies (from 1 July 2026)
  • Conveyancers (from 1 July 2026)
  • Trust and company service providers (from 1 July 2026)
  • High-value dealers in precious metals and stones (from 1 July 2026)

If you are a Tranche 2 entity, your AML policies and procedures must be operational by 1 July 2026. Starting now gives you time to develop, implement and train your staff on your documentation before that deadline arrives.

What One AML Develops for Your Business

We develop a complete set of AML/CTF policies and procedures tailored to your business. Every document we produce is grounded in your risk assessment findings and written for your specific operating environment.

AML/CTF Policy Your overarching policy document sets out your business's commitment to AML/CTF compliance, the scope of your obligations, your governance structure and the responsibilities of your AML/CTF Compliance Officer and broader staff.

Customer Due Diligence Procedures Your CDD procedures cover how you identify and verify customers and beneficial owners, how you apply a risk-based approach to customer onboarding and how you conduct ongoing monitoring of existing customer relationships.

Enhanced Due Diligence Procedures For higher-risk customers, including PEPs, customers from high-risk jurisdictions and those with complex ownership structures, your enhanced due diligence procedures set out the additional steps your business must take before and during the relationship.

PEP and Sanctions Screening Procedures These procedures set out how and when your business screens customers and transactions against PEP lists and sanctions databases, and what steps to take when a match is identified.

Transaction Monitoring Procedures Your transaction monitoring procedures define the indicators and thresholds your business uses to identify unusual or potentially suspicious activity, and the process for escalating and investigating alerts.

Suspicious Matter Reporting Procedures These procedures set out the process for identifying suspicious activity, conducting an internal investigation, escalating to your Compliance Officer and lodging a Suspicious Matter Report with AUSTRAC where required.

Record-Keeping Procedures Your record-keeping procedures cover what records must be kept, in what format, for how long and who is responsible for maintaining them. Under the AML/CTF Act, most records must be retained for a minimum of seven years.

Staff Training Procedures These procedures set out your obligations to provide AML/CTF training to relevant staff, how training is delivered, how completion is recorded and how training content is kept current.

AML Policies and Procedures as Part of Your Broader Program

Your AML policies and procedures do not stand alone. They sit within your broader AML/CTF program and must be directly connected to your risk assessment. The risks identified in your assessment determine the controls built into your procedures. If your risk assessment changes, your procedures need to be updated to reflect it.

One AML develops your policies and procedures as part of an integrated compliance framework. If you need a full AML/CTF program build, including risk assessment, program documentation, registers and training, our consulting packages cover all of it. See our [AML/CTF Program] and Consulting and Advisory pages for more details.

Keeping Your AML Policies and Procedures Current

Your documentation is not a one-time exercise. AUSTRAC requires reporting entities to review and update their AML/CTF policies and procedures regularly and whenever there are material changes to their business or risk environment.

You should review and update your documentation when:

  • You introduce new products, services or delivery channels
  • You take on new customer types or markets
  • Your business structure or ownership changes
  • AUSTRAC issues new guidance or regulatory expectations change
  • Your independent audit identifies gaps or weaknesses in your current documentation
  • There are significant changes in ML/TF typologies relevant to your industry

Our ongoing advisory and AMLCO Support Services are available to help you keep your documentation current and your compliance position strong.

Why Choose One AML for AML Policies and Procedures?

We have helped over 1,000 reporting entities across Australia and New Zealand build and maintain effective AML/CTF documentation. Our team has deep expertise across every regulated sector and knows what AUSTRAC expects to see in your policies and procedures.

  • Every document tailored to your specific business and risk profile
  • Grounded in your AML/CTF risk assessment findings
  • Written in plain language your staff can understand and apply
  • Covers all required components under the AML/CTF Act
  • Delivered as part of a full program build or as a standalone service
  • Ongoing review and update support available
  • 70+ verified Google reviews

We’re qualified to consult for all Phase 1 and 2 reporting entities across Australia.

Calculator and paperwork Icon

Accounting

The easy access and wide geographic spread of accounting services, coupled with accountants' gatekeeper role and use in every phase of ML/TF.
Piggy Bank Icon

Financial Services

Domestic and international evidence suggests that financial institutions are vulnerable to ML/TF. The Act. and regulations place obligations on Australian financial institutions to detect and deter ML/TF.
Scale Icon

Law

The easy access and wide geographic spread of legal services, coupled with lawyers’ gatekeeper role and use in every phase of ML/TF.
Certificate Icon

Other Captured Sectors

Other industries that are widely spread and easy to access by ML. The nature of these industries lends itself to all stages of ML/TF.
House Icon

Real Estate

The use of real estate in ML/TF is well-known and demonstrable. FIU research indicates real estate is the ML asset of choice.
Wallet Icon

Virtual Assets / Crypto

The easy access and wide geographic spread of VASP services, coupled with their pseudo-anonymous nature and use in every phase of ML/TF.

Frequently Asked Questions

What is the difference between Part A and Part B of an AML/CTF program?
Blue circular icon with a black question mark and upward arrow inside.
Part A covers your business-wide AML/CTF controls, including your risk assessment, policies and governance framework. Part B covers your customer due diligence procedures. Both parts are required under the AML/CTF Act.
How long does it take to build an AML/CTF program?
Blue circular icon with a black question mark and upward arrow inside.
It depends on the size and complexity of your business. For most small to mid-sized businesses, we can deliver a complete program within a few weeks of engagement. We recommend starting as early as possible, particularly if your obligations begin 1 July 2026.
Do I need an independent audit after my program is in place?
Blue circular icon with a black question mark and upward arrow inside.
Yes. The AML/CTF Act requires reporting entities to have their program independently reviewed at least every three years, or when requested by AUSTRAC. One AML also provides independent audit and review services.
Can One AML help if I already have a program but need it updated?
Blue circular icon with a black question mark and upward arrow inside.
Yes. We review and update existing AML/CTF programs to ensure they remain current with regulatory changes and reflect any changes to your business.

Build AML Policies and Procedures That Actually Work

Whether you are starting from scratch or updating existing documentation, One AML can help you develop AML policies and procedures that are compliant, practical and built for your business.