AML/CTF
AML/CTF Evidence Checklist: What Records To Keep For AUSTRAC Readiness
A practical AML/CTF evidence checklist for Australian businesses preparing records for AUSTRAC readiness, internal review, independent evaluation, board reporting and information requests.
9 min read | 2026-08-22
Evidence is where AML/CTF readiness becomes real
A business can understand AML/CTF obligations and still fail to prove readiness if the evidence is fragmented. The practical test is simple: can the business show what applies, who owns it, what has been implemented, what is overdue and where the supporting records are stored?
This evidence checklist is designed for internal readiness, adviser review, independent evaluation, board reporting and potential AUSTRAC information requests. It should be tailored to the services the business actually provides.
- Keep evidence linked to obligations, not just stored in folders.
- Record owner, status, approval, review date and supporting files.
- Separate scope records, program records, CDD records, reporting records and training records.
- Review evidence whenever services, customers or risk settings change.
Scope and governance evidence
Scope and governance records explain why the business believes AML/CTF applies, which services are captured, who is accountable and how decisions are reviewed. Without these records, a business may struggle to justify the shape of its program.
These records are especially important where only some services are captured or where the business has decided that AML/CTF does not apply to a particular service line.
- Business profile and entity details.
- Designated service assessment and outcome.
- AUSTRAC enrolment or registration records where applicable.
- Compliance officer or responsible person appointment.
- Senior manager approval records.
- Implementation plan and progress updates.
- Board, partner or executive review minutes.
Program, risk and policy evidence
The AML/CTF program should connect risk assessment, policies, procedures, systems and controls. A strong evidence pack shows the program version, approval, scope, risk basis and review history.
The risk assessment should be specific to the business. Generic statements are weaker than records showing customer types, services, delivery channels, jurisdictions, payment methods, transaction patterns and red flags.
- AML/CTF program and version history.
- ML/TF/PF risk assessment.
- Risk-to-control map.
- CDD and enhanced due diligence procedure.
- Suspicious matter reporting procedure.
- Record-keeping and privacy/security procedure.
- Independent evaluation or program review records.
CDD, reporting and operational records
Operational records prove that the business is not merely documenting controls but using them. These records should show how customers are checked, when matters are escalated, what reporting decisions were made and how exceptions are handled.
For professional services and real estate, these records may sit inside matter or transaction files. For dealers and virtual asset businesses, they may sit in transaction systems. The compliance team still needs a way to locate and evidence them.
- Customer identification and verification records.
- Beneficial ownership and control evidence.
- Source of funds or source of wealth evidence where relevant.
- Enhanced due diligence decisions and approvals.
- Suspicious matter escalation and reporting records.
- Threshold or transaction reporting evidence where relevant.
- Exception, breach and remediation records.
Training, personnel and review records
People records matter because AML/CTF controls depend on staff recognising risk and following the process. Training should be role-aware, tracked, refreshed and linked to the business services being provided.
Personnel due diligence, supervision, review and control testing records also help demonstrate that the business is monitoring whether the program works in practice.
- Training matrix and completion evidence.
- Role-based AML/CTF exposure assessment.
- Personnel due diligence records where required.
- Control testing plan and results.
- Audit or independent evaluation findings.
- Remediation actions and effectiveness review.
- Recurring review calendar.
How to make the evidence usable
The best evidence system is not the one with the most documents. It is the one where each important record is current, owned, linked, reviewable and easy to produce. That is what turns AML/CTF compliance from a panic exercise into an operating rhythm.
Complynce is designed to help with that operating layer: obligations, registers, evidence, actions, reports and audit trail inside one free AML/CTF workspace.
- Link every key document to an obligation or register record.
- Use status, owner, due date and review date fields.
- Separate draft evidence from approved evidence.
- Track remediation actions to closure.
- Use reports to prepare for internal audit, independent evaluation or information requests.
Next step
Check whether AML/CTF applies, then organise the evidence trail.
Use the free checker first. If AML/CTF applies, request the free Complynce AML/CTF Portal to manage obligations, records, evidence, actions and reports.
