Skip to main content

Review and Evaluation

A program written once and never revisited stops describing the firm within a year. The regime expects assurance work, and it treats three activities as separate things even though firms often run them together. Each answers a different question and produces a different record.

ActivityThe question it answersWho does it
Program maintenanceHas anything changed that the program should reflect?The firm, continuously
Effectiveness testingDo the controls in the program work?The firm itself, periodically
Independent evaluationDoes the program, as a whole, meet the requirements?Someone independent of it

Program maintenance

Maintenance is the ongoing work of keeping the program aligned with reality. Policies have to be reviewed and updated in response to a review of the firm's ML/TF risk assessment (s 26F(3)(c)), and in the circumstances the Rules specify. Section 26F(3)(d) requires the policies to be reviewed at the intervals or frequency the Rules specify, and in any event at least once every three years.

In practice this is a change driven activity with a backstop. Change of vertical mix, a new service line, a new delivery channel, a regulatory change, or a shift in the customer base can all make the risk assessment stale. When it is reviewed and updated, the policies have to follow.

Where a change does require a new version, the program is re-approved rather than quietly edited. Duely keeps every version, so you can answer both "what does our program say" and "what did it say in March".

The program maintenance register, showing recorded changes with their capture dates.The program maintenance register, showing recorded changes with their capture dates.
The program maintenance register, showing recorded changes with their capture dates.

Effectiveness testing

Effectiveness testing is the firm checking its own controls. It asks whether the program is doing what it claims: are due diligence records complete, are report deadlines met, are high risk customers escalated, is training happening.

Like the rest of the program, it should be proportionate to the nature, size and complexity of the firm's business (s 26F(1)(c)). What is proportionate for a two partner practice is not proportionate for a firm with several hundred staff.

Good testing samples real engagements rather than reviewing the process on paper, records what was found including the failures, and has someone senior sign off on the corrective action.

Independent evaluation

The independent evaluation is an evaluation of the firm's AML/CTF program conducted by someone independent of it. The obligation is in s 26F(4)(f), with further requirements in Rules s 5-10.

Two things are fixed:

  • The minimum frequency is at least once every three years. Section 26F(4)(f)(ii) sets that floor, and the frequency must in any event be appropriate to the nature, size and complexity of the business.
  • The AML/CTF Compliance Officer cannot perform it on the program they run. AUSTRAC expects the evaluator not to be the AML/CTF Compliance Officer or a member of the compliance team.

First evaluation deadlines for firms new to the regime are staggered under the transitional rules rather than all falling due at once.

AUSTRAC's guidance on this step is Step 5: Conduct an independent evaluation.

The evaluation's record is its findings, any adverse findings, and the action plan responding to them. Rules s 5-10 requires the evaluation report to go to the governing body and a senior manager, and the firm's policies to say how it responds to the findings. Duely records a senior manager's approval of the action plan, which is how the product captures that response rather than a legal requirement.

An independent evaluation record, showing the review outcome, any adverse findings, and the action plan.An independent evaluation record, showing the review outcome, any adverse findings, and the action plan.
An independent evaluation record, showing the review outcome, any adverse findings, and the action plan.

How Duely keeps them separate

The Program Builder covers your own program maintenance as it happens, and the assurance pages track effectiveness checks and independent evaluations as separate registers, mirroring the three obligations rather than merging them into one "review" concept.

  • Build your program, for what the program contains and how versions work.
  • Appoint your AMLCO, for the officer's duties, including reporting to the governing body at least every 12 months.
  • Record keeping, for retention of evaluation records.
  • Reporting, for the annual compliance report, which is a separate obligation reported on rather than assurance work.