Analytics and cookies

We use analytics cookies to understand which pages and calls to action are working. You can accept or decline non-essential tracking.

Essential site functionality continues either way. You can review the details in our Privacy Policy.

AML/CTF

AML/CTF Checklist Australia 2026: What Newly Regulated Businesses Need To Do

A 2026 AML/CTF checklist for newly regulated Australian businesses covering applicability, AUSTRAC enrolment, AML/CTF programs, CDD, reporting, training, evidence and review.

10 min read | 2026-08-22

Why a checklist is the right starting point

For newly regulated businesses, AML/CTF readiness can feel abstract until it becomes a sequence of concrete tasks. A checklist turns the reform into practical work: confirm applicability, enrol if required, appoint responsibility, create the program, assess risk, prepare customer due diligence, train staff, and keep records.

This article is designed as a business-readiness checklist, not legal advice. It should be used alongside AUSTRAC guidance and independent advice where needed. The goal is to help business owners and compliance managers understand what evidence they may need to organise.

  • Check if a designated service is provided.
  • Confirm enrolment or registration requirements.
  • Document the AML/CTF program and risk assessment.
  • Prepare CDD, reporting, training and record-keeping controls.
  • Keep an evidence trail for implementation and review.

Checklist 1: applicability and scope

The first checklist is the most important. If the business does not define scope correctly, everything after it can be too broad, too narrow or misdirected. Scope should be based on actual services, customer or client interactions, payment methods and Australian connection.

Do not rely only on the business name or sector. A practice, agency or dealer should be able to point to the service that created the AML/CTF trigger, or the reason no trigger applies.

  • Identify business type and legal entity.
  • List services provided to customers or clients.
  • Map services to designated-service triggers.
  • Record whether each service has an Australian connection.
  • Document why AML/CTF applies or does not apply.
  • Assign an owner for ongoing scope review.

Checklist 2: AUSTRAC readiness and ownership

If AML/CTF applies, the business needs clear ownership. That includes who will manage AUSTRAC enrolment or registration, who will own the AML/CTF program, who will approve changes and who will monitor ongoing compliance.

AUSTRAC guidance for newly regulated entities refers to enrolment through AUSTRAC Online within the required timeframe after providing a designated service. Businesses should keep evidence of decisions, submissions and receipts rather than relying on memory.

  • AUSTRAC Online account and enrolment status.
  • Compliance officer or responsible person appointment.
  • Senior manager or governing body approval pathway.
  • Implementation plan with owners and due dates.
  • Submission receipts, reference numbers and review records.

Checklist 3: program, risk and customer due diligence

The AML/CTF program should be more than a downloaded template. It should explain how the business identifies, mitigates and manages ML/TF/PF risk in the context of its own services, customer types, delivery channels, jurisdictions and transactions.

Customer due diligence should also be operational. The team needs to know what information to collect, when enhanced due diligence is triggered, how beneficial ownership is checked, and what happens when information cannot be verified.

  • AML/CTF program approved and version controlled.
  • ML/TF/PF risk assessment by customer, service, channel, geography and transaction pattern.
  • CDD procedure and identification requirements.
  • Beneficial ownership and control checks.
  • Enhanced due diligence triggers and escalation rules.
  • Ongoing CDD review points and transaction behaviour monitoring.

Checklist 4: reporting, training and records

A business should be ready to identify and escalate suspicious activity, keep relevant records, and prove that staff understand the process. Training should not be a one-off slide deck. It should be role-based, recorded, refreshed and connected to the actual services the business provides.

Record keeping is one of the easiest areas to underestimate. If records are spread across emails, folders and spreadsheets, the business may struggle to prove what was done, when, by whom and why.

  • Suspicious matter reporting process and escalation owner.
  • Threshold or transaction reporting consideration where relevant.
  • Training register for relevant personnel.
  • Personnel due diligence where required.
  • Record retention rules, access controls and evidence ownership.
  • Independent evaluation or review evidence where applicable.

Checklist 5: turn gaps into actions

The final checklist is about execution. Every missing policy, incomplete register, overdue training record or weak CDD process should become an assigned action with an owner, due date and evidence requirement.

That is where Complynce becomes useful. The free AML/CTF Portal is designed to turn readiness work into obligations, scope records, registers, evidence and reports instead of scattered documents.

  • Create actions for missing program documents and risk assessment gaps.
  • Link evidence to the relevant obligation or register record.
  • Track due dates for enrolment, training, policy approval and review.
  • Use reports for internal audit, board reporting or AUSTRAC information requests.
  • Review the checklist whenever services, customers or payment methods change.

Next step

Check whether AML/CTF applies, then organise the evidence trail.

Use the free checker first. If AML/CTF applies, request the free Complynce AML/CTF Portal to manage obligations, records, evidence, actions and reports.

Related Reading