Blog

Tranche 2

Why AUSTRAC Enrolment Alone Does Not Make an AML/CTF Programme Audit-Ready

Enrolment is one obligation. Audit readiness needs an implemented programme, an evidence map, governance and a plan for independent evaluation.

Enrolment proves you entered the regime. It says nothing about whether your controls work. An audit-ready programme needs four further things, and the one most often missing is not a policy but the ability to retrieve evidence that a control was actually performed on a named customer.

What does enrolment actually establish?

Enrolment is a legal requirement for reporting entities. It is not an approval of the quality of an organisation's AML/CTF programme, and AUSTRAC does not certify one at the point of enrolment.

Current guidance requires reporting entities to develop, maintain and comply with a programme tailored to their business. That programme must be documented, approved by a senior manager, and in place before designated services are provided. It also needs to be reviewed and updated, independently evaluated, and supported by records.

So a business that has completed enrolment has discharged one administrative obligation. The operating model that follows it is where the rest of the regime lives, and for audit and risk teams the question is whether the business can show the controls described in the programme are being performed.

That distinction is easy to lose internally, because enrolment produces something visible. There is a submission, a confirmation and an account number, and each of those feels like progress in a way that a customer due diligence workflow does not. A board that has been shown the confirmation can reasonably believe the project is finished, which is why the reporting discussed further down matters as much as the controls themselves.

Why is a paper-only programme the wrong diagnosis?

The risk is not that a programme is written in a document rather than in software. Plenty of well-run controls are documented and executed manually.

The risk is that documented policy and actual practice have diverged. A policy might require customer risk assessment, beneficial ownership verification, enhanced due diligence or screening, while the organisation has no reliable way to show those steps occurred on a particular customer on a particular date.

Automated screening is not a universal legal requirement, and it should not be presented as one. Technology becomes relevant where it is the organisation's chosen control for managing identified risk at its scale and complexity. What matters is that the control design is appropriate to the risk, implemented, followed consistently, and evidenced.

Divergence usually arrives gradually rather than by decision. A policy is written at the level the firm aspires to, volumes rise, an exception becomes a habit, and nobody revisits the document. The practical consequence is that the programme most likely to fail a review is not the one with a weak policy but the one with a strong policy that no longer describes the business.

What should an evidence map contain?

An audit-ready programme identifies what evidence demonstrates each control, and where that evidence lives. The useful version of this document names four things per obligation rather than one.

Obligation areaExample evidenceName in the map
GovernanceProgramme approval, governance minutesSystem of record
Risk assessmentCurrent ML/TF risk assessment, change historyOwner
AccountabilityCompliance officer appointment, reporting linesRetention period
Customer due diligenceCDD records, beneficial ownership evidenceRetrieval process
ScreeningPEP, sanctions and adverse media records where policy requires
Higher-risk customersEnhanced due diligence approvals and rationale
ReportingSuspicious matter escalation records, procedures
PeopleTraining attendance and competency records
AssuranceControl testing, exceptions, remediation actions

Naming the system of record, the owner, the retention period and the retrieval process for each row is what makes the map operational. A generic audit folder assembled after a request arrives is not the same artefact, and it tends to be built from whatever people can find rather than from what the policy promised.

How is independent evaluation different from a directed audit?

Under the reformed framework, AML/CTF policies must provide for independent evaluations of the programme. AUSTRAC says the evaluator should test the risk assessment, policy design, risk management, and compliance with the organisation's own policies. At a minimum an evaluation must occur at least once every three years, and transitional rules stagger the first evaluation deadlines for newly regulated entities.

That is not the same as an external audit directed by AUSTRAC under the Act. A regulator-directed audit is a supervisory or enforcement power. An independent evaluation is part of the reporting entity's own programme obligations.

Using the right term matters because the trigger, the purpose and the governance response differ. Treating a directed audit as though it were a routine evaluation understates it, and treating an evaluation as though it were an enforcement event tends to produce a defensive exercise rather than a useful one.

How do you test readiness rather than assume it?

Select a sample of recent customers and ask the compliance team to reconstruct the decision trail. Who was the customer, what information was collected, how was beneficial ownership established, what screening occurred, how were potential matches resolved, what risk rating was assigned, who approved any exception, and what ongoing monitoring applies.

Run it as an unannounced exercise on real files rather than as a walkthrough of the policy. The policy will describe the intended control; the sample shows the control that exists. Choose the sample across offices, service lines and risk ratings rather than taking the most recent files, which tend to be the best-kept.

If the evidence exists but takes days to assemble from spreadsheets, inboxes and personal drives, the control may still be operationally fragile. Retrieval time, completeness and version integrity are legitimate assurance concerns even where the underlying obligation prescribes no particular technology. Our Tranche 2 checklist sets out the evidence each step should leave behind.

What should management report on?

Not a single completeness percentage. A score of that kind averages a well-run control together with a material gap and hides the second one.

Report instead on which material controls are operating, which are partially operating, which are not yet operating, and what risk is being accepted or mitigated while work continues. Attach the trajectory, so the direction of travel is visible alongside the current state.

Useful supporting evidence includes approved programme changes, the results of customer-file testing, training completion, screening and match-review records, suspicious matter escalation exercises, independent evaluation planning, and the closure of previously identified issues. The point of that list is that every item is a record rather than an assurance, so a reader can check it.

Where a control is not yet operating, say what interim mitigation applies and who owns it. A gap with a named owner, an interim control and a target date reads as active risk management. The same gap with neither reads as an unmanaged one.

Where does technology fit?

Structured screening, monitoring, due diligence decisions and reporting records form part of an enterprise evidence trail, and centralising them reduces reliance on individually maintained files. That directly improves the retrieval test above, which is usually the weakest part of a new programme.

Audit readiness still needs the wider programme evidence, including governance, risk assessment, training, reporting and independent evaluation. A platform supports the operational layer. It does not replace the programme, and it does not replace the evaluator's judgement. The Tranche 2 hub covers the rest of that sequence.

Important information

This article provides general information about Australia's AML/CTF framework and does not constitute legal advice. Whether an obligation applies depends on the designated services provided and the circumstances of the business.

Independent evaluation timing depends on transitional rules and on your own enrolment details, so confirm your own deadline rather than assuming a general one. Reporting entities remain responsible for meeting their obligations under the AML/CTF Act, the Rules and applicable AUSTRAC guidance.

FAQ

Common questions.

Does AUSTRAC approve our AML/CTF programme when we enrol?
No. Enrolment is a legal requirement for reporting entities but it is not an assessment of programme quality. Current guidance requires reporting entities to develop, maintain and comply with a programme tailored to their business, documented, approved by a senior manager and in place before designated services are provided.
What makes a programme paper-only?
Not the medium. The risk is that documented policy and actual practice diverge. A policy may require customer risk assessment, beneficial ownership verification, enhanced due diligence or screening while the organisation has no reliable way to show those steps happened on a given customer on a given date.
Is automated screening legally required?
It is not a universal statutory requirement. Technology becomes relevant where it is the organisation's chosen control for managing identified risk at its scale and complexity. What matters is that the control design is appropriate, implemented, followed consistently and evidenced.
How often must an independent evaluation happen?
AML/CTF policies must provide for independent evaluations of the programme, and at a minimum an evaluation must occur at least once every three years. Transitional rules stagger the first evaluation deadlines for newly regulated entities, so check which deadline applies to your own AUSTRAC account number.
Is an independent evaluation the same as an AUSTRAC-directed external audit?
No, and the distinction matters. An independent evaluation is part of the reporting entity's own programme obligations. An external audit directed by AUSTRAC under the Act is a supervisory or enforcement power. The trigger, the purpose and the governance response are all different.

See MemberCheck against your own risk data.

Book a walkthrough with our compliance team and screen a real case in the first session.