THE AI COMMAND
LEARNING MODULE
TAIC-LM-G03
Anti-Money Laundering and
Counter-Terrorism Financing
Act 2006 (Cth)
From AUSTRAC obligations to AI-enabled compliance practice
Executive Summary

The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (the AML/CTF Act) is the Commonwealth statute that obliges Australian reporting entities to detect, deter, and disrupt the movement of illicit funds and the financing of terrorism. The Act is administered by the Australian Transaction Reports and Analysis Centre (AUSTRAC), which is both Australia's anti-money laundering regulator and its financial intelligence unit. The Act sits over a layered regime of customer due diligence, transaction monitoring, mandatory reporting, governance program design, and record-keeping. The regime was substantially reformed by the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024: since 31 March 2026 every reporting entity must maintain a documented money laundering and terrorism financing (ML/TF) risk assessment and AML/CTF policies in place of the former Part A and Part B program structure. From 1 July 2026 the Act extends to Tranche 2 reporting entities including law practices, accounting practices, real estate professionals, and dealers in precious metals and stones, materially enlarging the regulated population.
Why this matters
Australian financial services entities sit at the centre of the AML/CTF perimeter. Civil penalties for systemic breach run to tens of millions of dollars per contravention, and recent enforcement outcomes have crossed the billion-dollar threshold for Australian Authorised Deposit-taking Institutions (ADIs). Beyond the financial exposure, Boards and Senior Managers are accountable under the Financial Accountability Regime (FAR) for the soundness of AML/CTF controls, and APRA prudential standard CPS 230 captures AML/CTF reporting as a critical operation. The cost of getting this wrong is compounding: regulator action, FAR consequences, capital impact, and reputational loss.
What you will be able to do
- Read the AML/CTF Act 2006 (Cth) and identify which obligations apply to a given product, service, or business line.
- Decompose a customer or transaction scenario into the right obligation pathway (CDD, ECDD, SMR, TTR, IFTI, sanctions screening).
- Draft, review, and stress-test an ML/TF risk assessment and AML/CTF policies against AUSTRAC published guidance.
- Stand up a governed AI workflow in Claude or ChatGPT that drafts compliance artefacts without leaking customer data.
- Brief a Board or Senior Manager on Tranche 2 readiness with quantified gap evidence.
Regulatory and Strategic Context

Issuer and statutory authority
The AML/CTF Act 2006 (Cth) is an Act of the Commonwealth Parliament. It is supplemented by the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (the AML/CTF Rules), made under section 229 of the Act, which replaced the 2007 Rules Instrument from 31 March 2026 and carry binding regulatory detail. AUSTRAC publishes guidance, regulator priorities, and typology bulletins which, while not binding instruments, set the operational expectations a reasonable reporting entity should meet. The Financial Action Task Force (FATF) sets the international standards that Australia implements through this Act, and Australia is subject to FATF Mutual Evaluations on its compliance posture.
Scope of application
The Act applies to a person who provides a designated service. Section 6 of the Act lists the designated services in a series of tables. The longstanding tables cover financial services, bullion, and gambling, and the Tranche 2 reforms added services covering real estate, professional services, and dealers in precious metals and stones, with obligations commencing 1 July 2026. Item numbering has been amended over the life of the Act and practitioners should always work from the current consolidated version. The financial sector table is the longest and captures account-based services, lending, foreign exchange, derivatives, custodial services, life insurance investment products, superannuation services, and virtual asset services, the term that replaced digital currency exchange under the 2024 amendments. Since 31 March 2026 corporate groups operate as reporting groups, the structure that replaced designated business groups. A reporting group may nominate a lead entity to maintain group-wide AML/CTF policies, and members may share functions such as ongoing customer due diligence, but each reporting entity remains accountable for the obligations attaching to the designated services it provides.
The geographical reach of the Act is extra-territorial in two important ways. First, a service provided at or through a permanent establishment of the entity in Australia falls within scope even if the customer is overseas. Second, services provided by an Australian permanent establishment to a customer outside Australia carry full obligations. This matters for offshore branches, foreign subsidiaries, and cross-border product distribution.
Key dates and transitional periods
The Act commenced on 13 December 2006 with a phased implementation through 2008. Successive amendments expanded the regime, including the introduction of digital currency exchange registration effective 3 April 2018, later absorbed into the broader virtual asset service provider regime, and the strengthening of beneficial ownership and politically exposed person (PEP) requirements through Rules amendments.
The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 delivered the most substantial reform of the regime since commencement. Three dates matter.
- 31 March 2025. The reformed tipping off offence in section 123 commenced. The old blanket prohibition was replaced with an outcomes-based test: disclosing SMR-related information is prohibited where the disclosure would, or could reasonably be expected to, prejudice an investigation.
- 31 March 2026. For existing reporting entities, the prescriptive Part A and Part B program structure was replaced by a documented ML/TF risk assessment and AML/CTF policies. Reporting groups replaced designated business groups. The virtual asset service provider regime replaced digital currency exchange registration. The Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 replaced the 2007 Rules Instrument.
- 1 July 2026. Tranche 2 entities, including law practices, accounting practices, conveyancers, real estate professionals, and dealers in precious metals and stones, became reporting entities when they provide listed designated services. A new reporting entity must enrol with AUSTRAC within 28 days of first providing a designated service, and enrolment opened for the new population on 31 March 2026.
AUSTRAC's transitional posture favours entities that can demonstrate a good faith program build, a documented ML/TF risk assessment, and active engagement with the regulator. Entities that treated 31 March 2026 as a re-badging exercise rather than a redesign carry the highest supervisory risk.
If your program artefacts predate 31 March 2026, run the prompt below before your next governance committee. Upload only redacted, de-identified documents.
Interplay with adjacent frameworks
Three adjacent frameworks are essential to operate this Act in a financial services environment. The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) (TAIC-LM-G02) regulate the collection, use, disclosure, and storage of customer information used in CDD and SMR processes; APP 3 (collection), APP 6 (use and disclosure), and APP 11 (security) carry specific operational consequences. APRA prudential standard CPS 230 Operational Risk Management (TAIC-LM-G05) requires regulated entities to identify AML/CTF reporting and sanctions screening as critical operations and to set tolerance levels for disruption. The Charter of the United Nations Act 1945 (Cth) and the Autonomous Sanctions Act 2011 (Cth) impose a parallel sanctions screening regime against the DFAT Consolidated List that sits beside the AML/CTF Act and is enforced by DFAT, not AUSTRAC. ASIC market integrity rules interact at the trading and surveillance layer.
In practice, AML/CTF Compliance must operate as a node in a wider control mesh, not a stand-alone function. The largest enforcement outcomes have arisen where the AML node was structurally disconnected from product, technology, and risk reporting paths.
Core Concepts and Defined Terms

Defined terms
Central obligations
Designated service trigger
Obligations attach to the act of providing a designated service. Identification of which Item in s6 applies, and to what type of customer, is the first decision in any control design. Onboarding flows must be wired to the Item, not just to the product code; the same product can fall under different Items depending on customer type, channel, or jurisdiction.
Customer due diligence and ongoing CDD
Initial CDD must be carried out before the designated service is provided to a new customer, and ongoing CDD applies throughout the relationship. Identity must be verified using reliable and independent documentation or electronic data sources, and beneficial owners, being the individuals who ultimately own 25 per cent or more of the customer or exercise effective control, must be identified and verified. Under the reformed framework the detailed CDD requirements sit in the Act as amended and the AML/CTF Rules 2025. The former stand-alone Part B ACIP document is gone, but the entity's AML/CTF policies must still record how identification and verification are performed. Ongoing CDD includes transaction monitoring, periodic reviews, and event-driven reviews on red flags.
Enhanced due diligence triggers
ECDD is mandatory where the customer or transaction is rated as higher-risk, where a PEP relationship is identified, where a correspondent banking relationship is established, where the customer is in or transacting with a high-risk jurisdiction, or where the entity forms a suspicion. Senior management approval is required before a foreign PEP relationship is established or continued. The ECDD measures must be documented and proportionate to the risk, consistent with the AML/CTF Rules 2025.
Reporting obligations
SMRs are filed under s41 when a suspicion forms on reasonable grounds. The deadline is 24 hours for any matter that raises a suspicion of terrorism financing and 3 business days for all other suspicions. TTRs under s43 apply to transfers of physical currency of $10,000 or more, and IFTIs under s45 apply to international funds transfer instructions; both follow a 10 business day rule. All reports are filed through AUSTRAC Online and must contain the customer, transaction, and reasoning fields. The tipping off offence in s123 was reformed with effect from 31 March 2025: it now prohibits disclosing SMR-related information where the disclosure would, or could reasonably be expected to, prejudice an investigation, with a maximum penalty of two years imprisonment, 120 penalty units, or both. Disclosures for legitimate purposes, such as obtaining legal advice from an external lawyer, are permitted.
AML/CTF program design
Since 31 March 2026 the Act requires every reporting entity to document an ML/TF risk assessment and to maintain AML/CTF policies. The risk assessment must consider the entity's customer types, designated services, delivery channels, and the foreign jurisdictions it deals with, and must be kept up to date against defined review triggers. The AML/CTF policies are the enterprise-wide policies, procedures, systems, and controls that manage and mitigate the risks identified, proportionate to the nature, size, and complexity of the business. They must cover customer due diligence, transaction monitoring, reporting, employee due diligence and training, governance oversight, the AML/CTF compliance officer role, and independent evaluation. The governing body must approve both artefacts. This structure replaced the former Part A and Part B program required under the pre-reform Act.
Reporting groups
Reporting groups replaced designated business groups from 31 March 2026. A reporting group may nominate a lead entity that maintains group-wide AML/CTF policies, and members may share functions such as ongoing customer due diligence. Sharing the performance of a function does not transfer accountability: each reporting entity remains responsible for the obligations attaching to the designated services it provides and must evidence oversight of shared arrangements through assurance and escalation.
Sanctions screening interplay
Sanctions screening operates against the DFAT Consolidated List under a separate statute. AML/CTF systems generally house the screening engine because of overlapping data flows, but the legal authority and the obligation set are different. DFAT, not AUSTRAC, takes enforcement action for sanctions breaches. Many enforcement matters surface a hybrid AML/sanctions failure pattern.
Practical Application in Australian Financial Services

The next four worked examples translate the obligation set into operational artefacts. Each uses de-identified scenarios with merge field placeholders. No real customer data.
Example 1: Authorised Deposit-taking Institution (ADI)
Trigger event: A new business banking customer (Customer A, an Australian-incorporated private company with a parent in a high-risk jurisdiction) opens a transaction account and immediately receives a series of structured deposits totalling $148,000 over four business days.
Obligation activated: the relevant account-based designated service Item under s6. Section 41 triggers an SMR if a reasonable suspicion arises that the structured deposits may constitute structuring (a Division 400 Criminal Code offence). Section 43 triggers a TTR for any single deposit at or above the $10,000 threshold.
Artefact produced: A draft SMR narrative populated with Customer A's identifiers, the deposit pattern, the analyst's reasoning, and the attached transaction monitoring alert ID. A TTR record is generated automatically through the core banking system. The entity's AML/CTF policies trigger an ECDD review of beneficial ownership given the foreign parent.
Audit trail expected: Transaction monitoring alert metadata, analyst reasoning notes, supervisor approval, AUSTRAC submission receipt, ECDD case file, and the link back to the customer's ongoing CDD record. The artefact must be retained for seven years under s107 of the Act.
Example 2: General insurer
Trigger event: A new commercial property policy is issued to Customer B, a single-purpose entity. The premium is paid in cash by a third party at the broker's office and the insured property is in a regional area with limited recent claims activity.
Obligation activated: the relevant general insurance designated service Item under s6 is engaged for some general insurance products through specified channels. The cash premium triggers a TTR. The third-party payer triggers an ECDD enquiry into the source of funds and the relationship between the payer and the insured.
Artefact produced: An ECDD case file summarising the source-of-funds enquiry, third-party payer rationale, and approval trail. A TTR. Where suspicion crystallises, an SMR. The broker is reminded of its own AML/CTF obligations under any joint program arrangement.
Audit trail expected: The case file must show what was asked, what was answered, what evidence was sighted, and who approved continuation of the policy.
Example 3: Superannuation trustee
Trigger event: A member (Customer C) requests an early release of superannuation under compassionate grounds and provides supporting documentation that, on review, contains internal inconsistencies (different signatures, a recent address change, and a beneficiary nomination change in the prior month).
Obligation activated: the relevant superannuation designated service Item under s6 is engaged. ECDD triggers because of indicia consistent with elder abuse, identity-takeover fraud, or laundering of stolen funds. SMR consideration is mandatory.
Artefact produced: An ECDD memorandum, a fraud and abuse referral to the trustee's vulnerability framework, an SMR if the suspicion is reasonably held, and a hold on payment. Member-facing communication must be drafted carefully to avoid breaching s123 (tipping off).
Audit trail expected: Documented reasoning, version history of member communications, evidence of the fraud and abuse referral, AUSTRAC submission receipt, and a clear link to ongoing CDD updates.
Example 4: AFSL holder (managed investment scheme operator)
Trigger event: A wholesale investor (Customer D) subscribes to a unit trust through an Australian Financial Services Licence (AFSL) holder. The subscription is funded from a foreign jurisdiction with which Australia has a high-risk advisory in place. The investor's beneficial owners include a foreign PEP.
Obligation activated: the relevant managed investment scheme and securities designated service Items under s6. ECDD applies due to foreign PEP and high-risk jurisdiction. The entity's AML/CTF policies require senior management approval to enter or continue the relationship.
Artefact produced: An ECDD pack including beneficial ownership chart, source-of-wealth and source-of-funds evidence, screening results against the DFAT Consolidated List, foreign PEP risk acceptance memorandum signed by the senior manager, and ongoing monitoring profile.
Audit trail expected: Approval trail, screening match metadata, ongoing monitoring frequency, and a control linkage to FAR-accountable Senior Managers under the Financial Accountability Regime.
Visual Pack
The six visuals below are inline within the regulatory, conceptual, application, and AI workflow sections. Each is rendered as a designer-ready specification that a learning experience designer can take into Lucidchart, Whimsical, or Figma without further interpretation.
Visual 1: Regulatory authority map
Specification for a jurisdictional flowchart. Eight nodes, three layers, top-down vertical orientation.
Visual 2: SMR decision tree
Specification for a process diagram with a single entry point and four terminal states. Render as Mermaid flowchart for the designer.
flowchart TD
A[Trigger event: alert, transaction, customer behaviour, employee tip] --> B{Reasonable suspicion?}
B -- No --> C[Document and close. Update monitoring rules.]
B -- Yes, terrorism financing indicia --> D[Lodge SMR within 24 hours under s41]
B -- Yes, other AML indicia --> E[Lodge SMR within 3 business days under s41]
D --> F[Apply tipping off controls under s123]
E --> F
F --> G[Update transaction monitoring scenarios and customer risk rating]
Visual 3: Comparative table (AML/CTF Act vs FATF vs EU 6AMLD)
Visual 4: AML/CTF RACI
RACI key: R = Responsible, A = Accountable, C = Consulted, I = Informed.
Visual 5: Quantitative chart (illustrative)
Specification for a bar and line combination chart. X axis: financial year (FY22 to FY26). Y axis (left): AUSTRAC enforcement action volume (count). Y axis (right): aggregate civil penalty exposure ($m, illustrative). All figures must be labelled "illustrative" in the rendered visual.
Numbers in this table are illustrative only. They are not drawn from AUSTRAC enforcement data.
Visual 6: Five things to remember
Operating the AML/CTF Framework With AI

This section explains how to run the AML/CTF Act day to day with large language model support (Claude or ChatGPT, Enterprise tier) without ceding judgement, leaking customer data, or creating an audit-trail vacuum.
Use cases at scale
- Drafting SMR narratives from de-identified case data: analyst supplies structured indicators, model assembles the narrative.
- Mapping s6 designated service Items against a product catalogue to surface onboarding control gaps.
- Programme gap analysis: comparing the ML/TF risk assessment and AML/CTF policies against AUSTRAC guidance and flagging missing components.
- Control narrative drafting for new product approvals from a controls library.
- Board paper distillation: producing a 250 word executive summary from a 30 page program update.
- Regulator response triage: drafting first-pass replies to AUSTRAC RFIs ready for legal and senior manager review.
- Typology synthesis: pulling AUSTRAC bulletins and FATF reports into a single internal briefing.
- Tranche 2 readiness: comparing capability against new obligations and producing a remediation roadmap.
Project space setup
Claude Project
Step 1. In Claude.ai, create a Project "AUSTRAC AML CTF Workspace" on Enterprise or Team. Step 2. Upload knowledge sources: redacted ML/TF risk assessment and AML/CTF policies, AML/CTF Act 2006 (Cth) consolidated text, AML/CTF Rules 2025, AUSTRAC compliance guide, FATF 40 Recommendations, and a controls library extract. Step 3. Set the system prompt: "You are an AML/CTF compliance analyst for an Australian reporting entity. You operate under the AML/CTF Act 2006 (Cth), the AML/CTF Rules, AUSTRAC guidance, and FATF Recommendations. You never reproduce real customer identifiers. You always flag tipping off risk under s123. You always cite section, rule, or guidance for every conclusion. You produce drafts for human review." Step 4. Naming: TAIC-{entity}-{type}-{YYYYMMDD}-{version}. Step 5. Configure a Skill "smr-narrative" codifying the narrative template and validation rules.
ChatGPT Project or Custom GPT
Step 1. Create a Project (Plus, Team, or Enterprise) "AUSTRAC AML CTF Workspace". Step 2. Upload the same knowledge sources. Step 3. Use the same system prompt scaffold. Step 4. For Custom GPT, set Capabilities to file search only and disable web browsing for sensitive workflows. Step 5. On Enterprise, confirm no-training at workspace level and identity-provider integration with Microsoft 365 or Google Workspace. Step 6. Naming convention is identical.
Prompt library
The six prompt patterns below cover the recurring artefacts. Start with the one you will use most this week: drafting an SMR narrative from de-identified case data. De-identify every input first, pseudonyms and placeholders only, with the identity link held outside the model.
Prompt 1: Obligation mapping
Role: AML/CTF analyst. Context: an Australian {{ENTITY_TYPE}} is launching {{PRODUCT}}. Task: Map the product to the designated services Items in s6 of the AML/CTF Act and identify the obligations triggered. Constraints: cite section and Rules reference. Do not include any real customer data. Output Format: a table with columns Item, Service description, Customer scope, Obligations triggered, Open questions. Quality Bar: every Item must have an explicit citation. Any obligation flagged must reference the underlying section or Rule. Open questions must be specific.
Prompt 2: Control narrative drafting
Role: AML/CTF control owner. Context: control identifier {{CONTROL_ID}} sits in the {{DOMAIN}} pillar of the entity's AML/CTF policies. Task: Draft a control narrative covering objective, design, performance, evidence, and key risk indicator. Constraints: 350 to 450 words. No customer identifiers. Reference the relevant section of the Act or Rules and any AUSTRAC guidance. Output Format: structured headings as listed. Quality Bar: each section must contain at least one specific evidence artefact reference and one named owner role.
Prompt 3: Gap or maturity assessment
Role: AML/CTF program reviewer. Context: the entity's current ML/TF risk assessment and AML/CTF policies are uploaded. Task: Compare them against AUSTRAC compliance guide expectations and FATF Recommendations 9 to 23. Constraints: produce a maturity rating (1 to 5) per pillar and a remediation pack. Output Format: pillar table plus a remediation roadmap with priority, owner, due date placeholder. Quality Bar: every gap finding must cite the source. No score may be awarded without supporting evidence.
Prompt 4: Board paper executive summary
Role: AML/CTF Compliance Officer drafting for a Risk Committee. Context: the attached program update runs to 30 pages and covers risk, controls, incidents, and Tranche 2 readiness. Task: Produce a 250 word executive summary plus three recommendations. Constraints: plain English. Australian spelling. Cite all materially negative findings. Output Format: heading, summary, three numbered recommendations with named accountable owner. Quality Bar: every recommendation must be SMART and traceable to the underlying program finding.
Prompt 5: Regulator response drafting
Role: AML/CTF Compliance Officer drafting a response to an AUSTRAC notice. Context: the notice requests information on {{TOPIC}}. Task: Draft a first-pass response. Constraints: cite the request, the controlling Act provisions, and any prior correspondence. No customer-level data. Output Format: response letter with section headings matching the regulator's questions. Quality Bar: every paragraph supports a named claim. No speculative content. Marked DRAFT FOR LEGAL REVIEW.
Prompt 6: Self-disclosure drafting
Role: AML/CTF Compliance Officer. Context: an internal control failure may amount to a contravention. Task: Draft a self-disclosure letter to AUSTRAC. Constraints: facts only, no legal opinion. Reference timeline, customer impact, remediation, and root cause status. Output Format: letter with annexed timeline. Quality Bar: every fact sourced from the internal investigation file.
Governance, audit, privacy, and risk appetite controls
De-identification is mandatory. Real customer identifiers (name, customer number, account number, date of birth, address) must never be entered into a model prompt. Use stable pseudonyms and merge field placeholders. Where the analyst needs the link from pseudonym to underlying customer, that link is held outside the model context.
Human-in-the-loop checkpoints apply at every output stage. No SMR, regulator response, or board paper is filed or sent without a documented human review and senior manager sign-off. The model output is the draft, not the artefact.
Prohibited inputs include PII, market sensitive data, sanctions intelligence (DFAT-restricted material), claimant medical or financial vulnerability data, and any information protected by tipping off restrictions under s123. If a workflow requires this content, escalate to a controlled environment under the entity's data classification policy.
Retention and logging: every model interaction relevant to AML/CTF activity is logged through the Enterprise tenant logging facility, retained in line with the seven-year obligation in Part 10 of the Act (s107 and related), and made available to internal audit on request. Model selection: Enterprise SaaS with no-training is the standard; on-prem or private cloud is required where the workflow handles customer-level data; public consumer-tier is prohibited.
CPS 230: AML/CTF reporting is generally a critical operation for an APRA-regulated entity. The model workflow must therefore have a documented service provider risk assessment, a disruption tolerance, and an evidenced operational resilience test that includes failover to a non-AI workflow. APP alignment: APP 3, APP 6, and APP 11 drive the prompt hygiene rules above; APP 1 governs disclosure of AI assistance to customers where appropriate.
Quality assurance loop
The tipping off check in the rubric below deserves its own tool. Run every customer-facing draft connected to a live matter through this scan before it leaves the team.
Run this five-step QA rubric against every AI output before it leaves the analyst's desk.
- Source check. Every factual claim has a citable source. Every section or rule reference is correct.
- Privacy check. No real customer identifiers, no third-party PII, no sanctions intelligence.
- Tipping off check. No language that could disclose the existence of an SMR or a related investigation.
- Material accuracy check. The output's central conclusion would survive an internal audit interview.
- Evidence check. The output is annotated with the supporting evidence artefacts and would stand up at an AUSTRAC enforcement interview.
Red team prompt
Red team prompt to stress-test your own draft: "You are an AUSTRAC investigator reviewing this output. Identify five reasons it could be non-compliant, evasive, or unsupported. Cite the section or guidance you are testing against. Score 1 to 10 on credibility. Recommend the smallest edits that would lift the score by 3 points."
Scaling pattern
Operationalise across the team as follows. First, codify each prompt as a versioned template in the project space (v1.0, v1.1) with a change log. Second, run a weekly evaluation cadence sampling outputs against the QA rubric. Third, set KRIs: percentage of outputs failing the source check, percentage failing the privacy check, percentage requiring three or more revisions before sign-off. Fourth, treat each model release as a change event: re-run the evaluation set and only promote at parity or better with a rollback path. Fifth, maintain a register of accepted and rejected use cases with rationale and review date.
Common Pitfalls and Watch-outs
Six common failure modes recur in AML/CTF supervision and enforcement outcomes. Each is followed by a one-line corrective action.
- Treating the program as a static document rather than a living system. Corrective action: bind the program to the risk assessment, review at every material change, and date-stamp every revision.
- Confusing legal coverage with operational coverage. Corrective action: trace every Item in s6 from product approval to onboarding, monitoring, and reporting.
- Late SMR lodgement on terrorism financing matters. Corrective action: build a hard 24-hour SLA into the case management workflow with auto-escalation.
- Outsourcing transaction monitoring without retaining accountability. Corrective action: maintain a Senior Manager owner under FAR with documented service provider risk and a quarterly assurance pack.
- Over-reliance on screening engines without periodic recalibration. Corrective action: document the calibration cycle, false positive rate, and the threshold change governance.
- Tipping off through customer service scripts. Corrective action: require AML approval of any customer-facing communication where an investigation is in flight.
- Misclassifying virtual asset or cross-border services. Corrective action: re-walk s6 designations whenever a product, channel, or jurisdiction changes.
Decision Frameworks and Tools

Decision tree: Should I lodge an SMR?
Render as Mermaid for the designer.
flowchart TD
Q1[Has an alert, behaviour, or transaction triggered enquiry?] -- No --> Close[Document and close]
Q1 -- Yes --> Q2[Is the suspicion held on reasonable grounds?]
Q2 -- No --> Investigate[Investigate further. Document.]
Q2 -- Yes --> Q3{Indicia of terrorism financing?}
Q3 -- Yes --> SMR24[Lodge SMR within 24 hours under s41]
Q3 -- No --> SMR3[Lodge SMR within 3 business days under s41]
SMR24 --> S123[Apply tipping off controls under s123]
SMR3 --> S123
Maturity ladder for an AML/CTF program
Use this prompt with the ladder below to locate your program and draft the uplift case.
Self-check questionnaire
- Can I produce a current, dated, and governing body approved ML/TF risk assessment and AML/CTF policies in under 30 minutes?
- Can I trace any product or service in my entity to a specific Item in s6 of the Act?
- Have I lodged an SMR in the past 12 months and can I evidence the reasoning behind the decision?
- Has the program been independently reviewed within the last two to three years?
- Have I run a Tranche 2 readiness assessment if my entity, or its clients, are in scope from 1 July 2026?
- Is my AML/CTF AI workflow logged, governed, and consistent with APP 3, APP 6, and APP 11?
- Can my Senior Manager (FAR-accountable) speak to the entity's AML risk profile in their own words?
Further Reading and Authoritative Sources
Primary statute and rules
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth).
- Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (current compilation).
- Charter of the United Nations Act 1945 (Cth) and Autonomous Sanctions Act 2011 (Cth) (sanctions regime).
- Criminal Code Act 1995 (Cth) Division 400 (money laundering offences) and Division 102 (terrorist organisation offences).
Regulator and government publications
- AUSTRAC, AML/CTF Compliance Guide (current edition).
- AUSTRAC, Suspicious Matter Reports: A Guide for Reporting Entities.
- AUSTRAC, Reporting Groups Guidance.
- Attorney-General's Department, Tranche 2 Reform package and explanatory materials.
- APRA, CPS 230 Operational Risk Management.
- ASIC, Information Sheet 225 Digital Assets: Financial Products and Services.
International standards
- FATF, International Standards on Combating Money Laundering and the Financing of Terrorism and Proliferation (the 40 Recommendations).
- FATF, Mutual Evaluation Report Australia (most recent edition).
- Wolfsberg Group, Anti-Money Laundering Principles for Correspondent Banking.
Professional bodies
- Association of Certified Anti-Money Laundering Specialists (ACAMS) Australasia chapter resources.
- Governance Institute of Australia, Risk and Compliance Practice resources.
- Risk Management Institution of Australasia (RMIA), AML risk papers.
Closing
This module is one of the foundation modules in TheAICommand learning library for Australian financial services governance, risk, and compliance. It pairs with the AML/CTF assessment (TAIC-LM-G03-AMLCTFAct-Assessment) and with the cross-referenced modules listed on the cover.
Practical takeaways
Do this Monday
- Pull your current program artefacts and check the labels. If the documents still say Part A and Part B, schedule the conversion to a documented ML/TF risk assessment and AML/CTF policies; the reformed structure has applied since 31 March 2026.
- Trace one product from its s6 designated service Item through onboarding, monitoring, and reporting. If you cannot name the Item, neither can your controls.
- Test your SMR clock. Ask the team what happens when terrorism financing indicia appear at 4pm on a Friday; the 24 hour deadline under s41 is measured in hours, not business days.
- Review one recent customer-facing communication connected to an investigation against the reformed s123 test: could the wording reasonably be expected to prejudice an investigation?
- If your corporate group shares compliance functions, confirm the reporting group arrangement is documented and that each member can evidence its own accountability.
The compliance checklist
- Current, dated ML/TF risk assessment approved by the governing body, covering customer types, designated services, delivery channels, and foreign jurisdictions.
- AML/CTF policies proportionate to the nature, size, and complexity of the business, with a named AML/CTF compliance officer.
- Every product and service mapped to its designated service Item in s6, re-walked whenever a product, channel, or jurisdiction changes.
- Initial CDD completed before any designated service is provided; ongoing CDD, periodic reviews, and event-driven reviews evidenced.
- ECDD triggers documented, with senior management approval on file for every foreign PEP relationship.
- SMR workflow with a hard 24 hour escalation path for terrorism financing suspicions and 3 business days for all others.
- TTR and IFTI reporting reconciled against source systems, with the 10 business day deadlines monitored.
- Customer-facing scripts and template letters cleared against the reformed s123 tipping off test.
- Records retained for seven years under Part 10 of the Act, including logs of any AI-assisted drafting.
- Independent evaluation scheduled, with findings tracked to closure and reported to the governing body.
Your prompt library
The four prompt boxes in this module cover the reform gap review, SMR narrative drafting, the tipping off language scan, and the maturity assessment, and the six prompt patterns in the AI section run from obligation mapping to self-disclosure. Save them into your project space as versioned templates. When you need a fast answer in a meeting, this one earns a place on a sticky note:

