The working parts of an AML/CTF program
Customer identification, screening and ongoing monitoring, with the records AUSTRAC expects behind each check. Built on the Document Verification Service and data sources approved for government use.
What AUSTRAC expects a program to do
The AML/CTF Act sets the obligations. These are the ones our checks carry.
Customer identification
Verify identity against reliable, independent sources before providing a designated service. DVS and government-record checks meet that standard.
Watchlist screening
Check customers against sanctions and PEP lists at onboarding, and again as the lists change.
Ongoing due diligence
Monitor customers through the relationship, with re-checks triggered by data changes rather than calendar reminders.
Reporting evidence
SMRs and annual compliance reports need the record of what was checked and when. It's kept automatically.
What runs this use case
Runs the program day to day: screening at onboarding, re-screening when lists change, and alerts your team reviews with the evidence attached.
About WatchEyearrow_forwardDVS document checks and data verification for the KYC step, run one at a time in the portal.
About IDFEXarrow_forwardThe same identification and screening checks, run from inside your own onboarding systems.
Explore the APIarrow_forwardWalk through a program against your obligations
Book a demo and we'll map the checks to your AML/CTF program, then run them on test customers.
Common questions about AML/CTF compliance
If your question isn't covered here, ask our team.
What does AUSTRAC require of a reporting entity?
add
Five things, in sequence:
- Enrolment with AUSTRAC
- A written AML/CTF program, based on your ML/TF risk assessment
- Customer identification before you provide a designated service
- Ongoing customer due diligence through the life of the relationship
- Reporting — suspicious matter reports, threshold transaction reports and annual compliance reports
How much detail each of these requires depends on your designated services and what your risk assessment concluded about them. A firm providing one low-risk service and a bank do not carry the same program, but they carry the same obligations.
What has to happen before we provide a designated service?
add
Customer identification, verified against reliable, independent sources, not self-reported details.
The timing is the part that catches organisations out. The obligation is to verify before providing the designated service, so a process that onboards the customer first and verifies within a few days is not compliant regardless of how quickly the verification eventually completes.
This is why the checks need to return in seconds, not hours. If verification is fast enough to sit inside the sign-up flow, the sequencing takes care of itself.
Which data sources sit behind the checks?
add
Identity checks run against the government's Document Verification Service and an Australian reference universe of roughly 2 billion records. Screening data is aggregated from official sanctions lists and PEP registers worldwide, across more than 268 countries.
For ongoing monitoring, each source is a separate monitor you can schedule independently:
- PEP and Sanction — global PEP lists and international sanctions
- Adverse Media — negative news, with AI-generated summaries
- Court — civil and criminal case records
- Banned or Disqualified Persons
- Deceased — including the Australian Death Check register
- Business and UK Business — ASIC and Companies House
- Phone and Real Estate — connectivity, and address listing history
The sourcing is what makes these checks count for compliance purposes. AUSTRAC's standard is reliable and independent, which excludes self-reported information no matter how carefully it is collected.
How often are customers re-screened?
add
On a schedule you choose, set per monitor, not globally.
The options run from daily, through weekdays, weekends or a nominated day of the week, to the 1st or 15th of the month, both, or quarterly. Scheduled monitors run automatically overnight and screen every entity in the program; if anything new is found, an event is created and the program's report email addresses are notified.
A program can carry several monitors at different cadences (PEP and sanctions daily, adverse media weekly, court screening quarterly), so you can put frequency where the risk is instead of running every source at the same rate.
Choosing the cadence is a real compliance decision, not a preference. The interval you set is the maximum time a newly sanctioned customer can sit in your book unnoticed, so it is worth setting deliberately and recording why.
What records are kept for each check?
add
What was checked, against which source, the result, the timestamp, and the operator who ran it.
Those records support both directions of the reporting obligation. Suspicious matter reports and annual compliance reports need the evidence of what was checked and when; an AUSTRAC request or an audit needs the same material assembled per customer.
Records can be exported at any time, and because they are produced by the checks themselves there is no separate filing step to be missed.
What do we have to report, and when?
add
Three things, on different triggers:
- Suspicious matter reports — when you form a suspicion, on the timeframe set by the Act
- Threshold transaction reports — for cash transactions at or above the reporting threshold
- Annual compliance reports — covering how your program operated over the year
The common failure point is not the filing itself but the evidence behind it. An SMR has to reference what was checked and observed, and an annual compliance report has to describe a program that demonstrably ran. Both are straightforward when the per-check record already exists and difficult when it has to be reconstructed.
We are a Tranche 2 firm. Does this apply to us?
add
Yes. The obligations are the same, scaled to your designated services.
Tranche 2 brought lawyers, conveyancers, accountants, real estate professionals, dealers in precious metals and stones, and trust and company service providers into the regime. The Act does not set a lighter standard for them; it sets the same standard against a smaller set of services.
What differs is delivery. Most Tranche 2 firms run checks from a browser instead of building an integration, and their programs are sized accordingly. The Tranche 2 use case covers the specifics.
Can we start with a single obligation?
add
Yes. The checks run independently of each other, so there is no requirement to implement everything at once.
Many organisations start with customer identification or screening, the two that are hardest to do manually and most immediately visible in a review, and add ongoing monitoring later, once the first part is running properly.
That sequencing is usually the right one. A screening capability that works reliably is worth more than three capabilities that are half-configured, and the records from the first obligation are useful evidence on their own.
Other use cases
Adverse media screening
Adverse media coverage, court records and corporate data for EDD reviews and pre-investment screening.
Read morearrow_forward shield_personFinancial crime management
Enhanced customer due diligence and ongoing monitoring for higher-risk customers.
Read morearrow_forward gavelTranche 2 compliance
An AML/CTF program for lawyers, accountants and real estate agents brought into scope by Tranche 2.
Read morearrow_forwardTalk to us about AML/CTF compliance
SOME OF OUR TRUSTED CLIENTS
Request a Demo
"*" indicates required fields
Call 03 9948 4089 · sales@globaldata.net.au
