Build Your AML/CTF Program
An AML/CTF program is the firm level document that says how the firm will meet its obligations in practice. It is the standard the firm is held to, so it has to describe what the firm does rather than what it would like to do.
What a program contains
Under the reformed regime, a program consists of two things:
- An ML/TF risk assessment: the firm's assessment of the money laundering and terrorism financing risk it faces, given the services it provides, the customers it serves, and how it delivers them.
- AML/CTF policies: the policies and procedures that respond to that assessment: how the firm identifies and verifies customers, monitors them, reports, keeps records, trains staff, and governs all of it.
Who approves it
A program must be approved before it takes effect, and approval is a governed act. The approver's identity and the version they approved are recorded, and the approved version supersedes any earlier one rather than overwriting it.
The law requires a senior manager to approve the program (s 26P(1)), and updates to the risk assessment to be reported to the governing body (s 26P(2)). Duely records that approval and adds three conditions of its own:
- An AML/CTF Compliance Officer must be appointed. A program cannot be approved without one, so appointing your AMLCO comes first.
- The person approving must be approval capable: Admin, Approver and AMLCO roles can approve; staff cannot.
- Where the author of the draft can approve and another approval capable member exists, they must ask that person rather than approving their own work.
Personnel due diligence is deliberately not an approval gate. Approving the firm's first program cannot require it, because the personnel due diligence process only exists once a program does. It becomes a hard gate later, on suspicious matter report submission and on the approval of continued high risk or enhanced due diligence cases.
The program belongs to the firm and is versioned. Previous versions are retained, so you can show what your program said at a given point in time rather than what it says today.
AUSTRAC's guidance on this is Develop your AML/CTF program, which sets out the steps AUSTRAC expects a firm to work through.


Reviewing it
A program has to stay aligned with how the firm operates, and the regime expects that to be tested rather than assumed.
Three activities are easy to conflate:
| Activity | What it is |
|---|---|
| Program maintenance | Recording changes to the program as the firm changes, with the reasoning |
| Effectiveness testing | Checking that the controls in the program work |
| Independent evaluation | An evaluation by someone independent of the program's operation |
The independent evaluation has a statutory basis and a minimum frequency. It is covered on Review and evaluation, including who may perform it and why the AML/CTF Compliance Officer cannot evaluate the program they run.
The law requires review when things change, and at least every three years (s 26D(1)(b), s 26F(3)(d)). Many firms review annually as well: check that the risk assessment still reflects the business, that the policies still match the assessment, and that any change made during the year is recorded.
Building it in Duely
Duely's Program Builder is a guided wizard that produces the program from your answers, parameterised by your firm's vertical. It runs through three steps (risk assessment, personnel and governance, and customer due diligence), with a fourth stage covering program maintenance generated automatically into the document rather than asked as questions. The output is a versioned PDF that becomes your program of record.
For the step by step walkthrough, see Program Builder. The wizard collects the answers, the answers generate the document, and the document is what the firm is held to.
Related pages
- Appoint your AMLCO, a precondition for approval.
- Customer due diligence, which the program must describe.
- Review and evaluation, for the independent evaluation duty.
- Program Builder, for the product walkthrough.