Enrolment proves you entered the regime. It says nothing about whether your controls work. An audit-ready programme needs four further things, and the one most often missing is not a policy but the ability to retrieve evidence that a control was actually performed on a named customer.
What does enrolment actually establish?
Enrolment is a legal requirement for reporting entities. It is not an approval of the quality of an organisation's AML/CTF programme, and AUSTRAC does not certify one at the point of enrolment.
Current guidance requires reporting entities to develop, maintain and comply with a programme tailored to their business. That programme must be documented, approved by a senior manager, and in place before designated services are provided. It also needs to be reviewed and updated, independently evaluated, and supported by records.
So a business that has completed enrolment has discharged one administrative obligation. The operating model that follows it is where the rest of the regime lives, and for audit and risk teams the question is whether the business can show the controls described in the programme are being performed.
That distinction is easy to lose internally, because enrolment produces something visible. There is a submission, a confirmation and an account number, and each of those feels like progress in a way that a customer due diligence workflow does not. A board that has been shown the confirmation can reasonably believe the project is finished, which is why the reporting discussed further down matters as much as the controls themselves.
Why is a paper-only programme the wrong diagnosis?
The risk is not that a programme is written in a document rather than in software. Plenty of well-run controls are documented and executed manually.
The risk is that documented policy and actual practice have diverged. A policy might require customer risk assessment, beneficial ownership verification, enhanced due diligence or screening, while the organisation has no reliable way to show those steps occurred on a particular customer on a particular date.
Automated screening is not a universal legal requirement, and it should not be presented as one. Technology becomes relevant where it is the organisation's chosen control for managing identified risk at its scale and complexity. What matters is that the control design is appropriate to the risk, implemented, followed consistently, and evidenced.
Divergence usually arrives gradually rather than by decision. A policy is written at the level the firm aspires to, volumes rise, an exception becomes a habit, and nobody revisits the document. The practical consequence is that the programme most likely to fail a review is not the one with a weak policy but the one with a strong policy that no longer describes the business.
What should an evidence map contain?
An audit-ready programme identifies what evidence demonstrates each control, and where that evidence lives. The useful version of this document names four things per obligation rather than one.
| Obligation area | Example evidence | Name in the map |
|---|---|---|
| Governance | Programme approval, governance minutes | System of record |
| Risk assessment | Current ML/TF risk assessment, change history | Owner |
| Accountability | Compliance officer appointment, reporting lines | Retention period |
| Customer due diligence | CDD records, beneficial ownership evidence | Retrieval process |
| Screening | PEP, sanctions and adverse media records where policy requires | |
| Higher-risk customers | Enhanced due diligence approvals and rationale | |
| Reporting | Suspicious matter escalation records, procedures | |
| People | Training attendance and competency records | |
| Assurance | Control testing, exceptions, remediation actions |
Naming the system of record, the owner, the retention period and the retrieval process for each row is what makes the map operational. A generic audit folder assembled after a request arrives is not the same artefact, and it tends to be built from whatever people can find rather than from what the policy promised.
How is independent evaluation different from a directed audit?
Under the reformed framework, AML/CTF policies must provide for independent evaluations of the programme. AUSTRAC says the evaluator should test the risk assessment, policy design, risk management, and compliance with the organisation's own policies. At a minimum an evaluation must occur at least once every three years, and transitional rules stagger the first evaluation deadlines for newly regulated entities.
That is not the same as an external audit directed by AUSTRAC under the Act. A regulator-directed audit is a supervisory or enforcement power. An independent evaluation is part of the reporting entity's own programme obligations.
Using the right term matters because the trigger, the purpose and the governance response differ. Treating a directed audit as though it were a routine evaluation understates it, and treating an evaluation as though it were an enforcement event tends to produce a defensive exercise rather than a useful one.
How do you test readiness rather than assume it?
Select a sample of recent customers and ask the compliance team to reconstruct the decision trail. Who was the customer, what information was collected, how was beneficial ownership established, what screening occurred, how were potential matches resolved, what risk rating was assigned, who approved any exception, and what ongoing monitoring applies.
Run it as an unannounced exercise on real files rather than as a walkthrough of the policy. The policy will describe the intended control; the sample shows the control that exists. Choose the sample across offices, service lines and risk ratings rather than taking the most recent files, which tend to be the best-kept.
If the evidence exists but takes days to assemble from spreadsheets, inboxes and personal drives, the control may still be operationally fragile. Retrieval time, completeness and version integrity are legitimate assurance concerns even where the underlying obligation prescribes no particular technology. Our Tranche 2 checklist sets out the evidence each step should leave behind.
What should management report on?
Not a single completeness percentage. A score of that kind averages a well-run control together with a material gap and hides the second one.
Report instead on which material controls are operating, which are partially operating, which are not yet operating, and what risk is being accepted or mitigated while work continues. Attach the trajectory, so the direction of travel is visible alongside the current state.
Useful supporting evidence includes approved programme changes, the results of customer-file testing, training completion, screening and match-review records, suspicious matter escalation exercises, independent evaluation planning, and the closure of previously identified issues. The point of that list is that every item is a record rather than an assurance, so a reader can check it.
Where a control is not yet operating, say what interim mitigation applies and who owns it. A gap with a named owner, an interim control and a target date reads as active risk management. The same gap with neither reads as an unmanaged one.
Where does technology fit?
Structured screening, monitoring, due diligence decisions and reporting records form part of an enterprise evidence trail, and centralising them reduces reliance on individually maintained files. That directly improves the retrieval test above, which is usually the weakest part of a new programme.
Audit readiness still needs the wider programme evidence, including governance, risk assessment, training, reporting and independent evaluation. A platform supports the operational layer. It does not replace the programme, and it does not replace the evaluator's judgement. The Tranche 2 hub covers the rest of that sequence.
Important information
This article provides general information about Australia's AML/CTF framework and does not constitute legal advice. Whether an obligation applies depends on the designated services provided and the circumstances of the business.
Independent evaluation timing depends on transitional rules and on your own enrolment details, so confirm your own deadline rather than assuming a general one. Reporting entities remain responsible for meeting their obligations under the AML/CTF Act, the Rules and applicable AUSTRAC guidance.



